CVE-2025-54820
8.1Fortinet · FortiManager
A stack-based buffer overflow in Fortinet FortiManager allows unauthenticated remote attackers to execute unauthorized commands via crafted network requests.
Executive summary
A critical stack-based buffer overflow vulnerability in Fortinet FortiManager may allow unauthenticated remote attackers to achieve unauthorized command execution.
Vulnerability
The vulnerability is a stack-based buffer overflow (CWE-121) occurring in FortiManager, which can be triggered by an unauthenticated remote attacker sending specifically crafted requests to the service. Successful exploitation potentially allows the attacker to execute arbitrary commands if the service is enabled and stack protections are bypassed.
Business impact
The potential for unauthorized command execution poses a severe risk to the integrity and confidentiality of the management infrastructure. Given the CVSS score of 8.1, this vulnerability represents a high-severity threat that could lead to full system compromise, providing attackers with a foothold to propagate through the network or disrupt critical management operations.
Remediation
Immediate Action: Upgrade to FortiManager version 7.6.0, 7.4.3, 7.2.11, or 6.4.16 or above to resolve the underlying buffer overflow flaw.
Proactive Monitoring: Monitor network traffic for unusual patterns or spikes in requests directed at the FortiManager management interface, and review system logs for signs of unauthorized access or service crashes.
Compensating Controls: Deploy Web Application Firewall (WAF) or Intrusion Prevention System (IPS) signatures if available from the vendor to inspect and drop malicious requests targeting the vulnerable management service until patching is complete.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a significant risk to the management plane and should be addressed as a high priority. Organizations must verify their current FortiManager firmware versions against the provided list and schedule emergency maintenance windows to apply the necessary patches immediately to prevent potential exploitation.