216.73.216.6

CVE-2025-32756: FortiVoice Zero-Day Exploit Alert

· Published 14/05/2025 13:56 · Modified 21/05/2025 20:05

Export JSON

Essential information

Published
14/05/2025 13:56
Modified
21/05/2025 20:05
Tags
2025-05-14 CVE-2025-32756 buffer overflow credential-capture fortinet fortivoice network-scan patch remote code execution zero-day
Related entities
1 vulnerabilities (cve), 6 observables, 13 techniques (mitre)

Description

A critical vulnerability () in multiple products, including , has been actively exploited. The flaw is a stack-based that allows without authentication. Attackers can gain full control of affected systems, access sensitive data, and pivot to other internal networks. The vulnerability stems from an enabled fcgi debugging option, which is not a default setting. has released patches and recommends immediate action. Detection methods include checking for enabled fcgi debugging and monitoring specific log entries. The threat actor has been observed conducting network scans, deleting crash logs, and enabling FCGI debugging to capture credentials.

External references