CVE-2025-25249 , Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
A CISA KEV · · CVE-2025-25249
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- CVSS
- 8.1
- EPSS
- 1%
- KEV due date
- 12 September 2026
Affected versions
Key insight
CISA has added CVE-2025-25249 to the Known Exploited Vulnerabilities (KEV) catalog and prioritizes this security issue under BOD-26-04 guidance, setting a remediation deadline of 2026-09-12.
Description
CVE-2025-25249 is a heap-based buffer overflow vulnerability affecting multiple Fortinet products, classified by CISA as actively exploited and added to the KEV catalog. The vulnerability potentially enables remote code execution under specific conditions. Fortinet solutions are commonly deployed as central security gateways and client protection tools. CISA has set a remediation deadline of 2026-09-12 under BOD-26-04 guidance and mandates organizations to prioritize security updates or discontinue product use if mitigations are unavailable.
Risk score
- cvss base
- 81.00
- kev bonus
- 20.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 101.00
- industry weight
- 1.21
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational
MITRE ATT&CK mapping
1 TTPProcedure details
| Technique | Tactic | Procedure | Conf. | Source |
|---|---|---|---|---|
| T1190 Exploit Public-Facing Application | Initial Access | Exploitation of a heap-based buffer overflow vulnerability (CVE-2025-25249) in Fortinet multiple products, likely through publicly accessible services, to gain unauthorized access. | medium | llm |