Back

CRITICAL KEV

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie

Published May 13, 2025 ·Due Jun 4, 2025

Description

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.

Affected products

Remediation

Vendor solution

Upgrade to FortiNDR version 7.6.1 or above Upgrade to FortiNDR version 7.4.8 or above Upgrade to FortiNDR version 7.2.5 or above Upgrade to FortiNDR version 7.0.7 or above Upgrade to FortiCamera version 2.1.4 or above Upgrade to FortiRecorder version 7.2.4 or above Upgrade to FortiRecorder version 7.0.6 or above Upgrade to FortiRecorder version 6.4.6 or above Upgrade to FortiVoice version 7.2.1 or above Upgrade to FortiVoice version 7.0.7 or above Upgrade to FortiVoice version 6.4.11 or above Upgrade to FortiMail version 7.6.3 or above Upgrade to FortiMail version 7.4.5 or above Upgrade to FortiMail version 7.2.8 or above Upgrade to FortiMail version 7.0.9 or above

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fortinet
Published May 13, 2025
Updated Feb 26, 2026
Reserved Apr 10, 2025
CISA Vulnrichment
Updated May 15, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a