CVE-2025-24477

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12...

Basic Information

CVE State
PUBLISHED
Reserved Date
January 21, 2025
Published Date
July 15, 2025
Last Updated
February 10, 2026
Vendor
Fortinet
Product
FortiOS
Description
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specially crafted CLI command

CVSS Scores

CVSS v3.1

4.0 - MEDIUM

Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:U/RC:C

SSVC Information

Exploitation
none
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2025-10-26 22:32:03 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-10-26 22:32:03 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel