CISA added CVE-2025-25249, a pre-auth heap-based buffer overflow across Fortinet FortiOS, FortiSwitchManager, and FortiSASE, to the Known Exploited Vulnerabilities catalog on 2026-09-09, with a three-day remediation deadline.
What Is It
CVE-2025-25249 is a heap-based buffer overflow (CWE-122, with NVD also assigning CWE-787, out-of-bounds write) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE. An attacker can execute unauthorized code or commands by sending specially crafted packets to an affected device.
Scoring is split. Fortinet PSIRT rates it CVSS 3.1 8.1 (HIGH) with high attack complexity: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. NVD rates it 9.8 (CRITICAL) with low attack complexity: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Both agree on network attack vector, no privileges, no user interaction, and total confidentiality/integrity/availability impact.
Why It Matters
CISA's KEV listing confirms active exploitation in the wild. The accompanying SSVC decision records exploitation status as active, automatable as no, and technical impact as total. Ransomware campaign use is listed as Unknown.
The affected products are network edge and management devices reachable over the network with no authentication required, and the KEV entry flags forensic triage as required (forensicTriage: Yes), meaning compromise assessment, not just patching, is in scope.
CISA's KEV entry is the only exploitation source this brief relies on. No specific tooling, malware family, or named threat actor is attributed to exploitation of CVE-2025-25249 by any source cited here.
What's Vulnerable
Per the NVD description:
- FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17, and 6.4.0–6.4.16
- FortiSwitchManager 7.2.0–7.2.6 and 7.0.0–7.0.5
- FortiSASE: named in the KEV short description; CPE data references versions 25.1.39 and 25.1.51
NVD CPE ranges indicate fixes at FortiOS 6.4.17, 7.0.18, 7.2.12, 7.4.9, and 7.6.4. Siemens RUGGEDCOM APE1808 is also listed as affected via a third-party advisory.
Patch Status
KEV due date is 2026-09-12: three days after listing. Required action: apply mitigations per vendor instructions in compliance with CISA BOD 26-04 and the Forensics Triage Requirements. For cloud services, follow applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines.
Sources
- Fortinet PSIRT FG-IR-25-084; https://fortiguard.fortinet.com/psirt/FG-IR-25-084
- NVD, CVE-2025-25249, https://nvd.nist.gov/vuln/detail/CVE-2025-25249
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25249
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- Siemens ProductCERT SSA-864900; https://cert-portal.siemens.com/productcert/html/ssa-864900.html
- SOCRadar, PivotC2 FortiGate RAT, https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/ (unverified third-party reporting; listed for further reading only; no claim in this brief rests on it)