216.73.216.6

Security Incident Response Team

· Published 14/05/2025 18:57 · Modified 21/05/2025 20:32

Export JSON

Essential information

Published
14/05/2025 18:57
Modified
21/05/2025 20:32
Tags
2025-05-14 CVE-2025-32756 buffer overflow credential-theft forticamera fortimail fortindr fortirecorder fortivoice log manipulation network scanning remote code execution
Related entities
1 vulnerabilities (cve), 6 observables, 13 techniques (mitre)

Description

A critical vulnerability in various Fortinet products allows remote attackers to execute arbitrary code via crafted HTTP requests. Observed exploitation on involved , erasing system logs, and enabling fcgi debugging to capture credentials. Affected products include , , , , and across multiple versions. The threat actor used specific IP addresses and modified system files and settings. Indicators of compromise include added malicious files, modified cron jobs, and altered configuration files. Fortinet recommends upgrading to patched versions or disabling the HTTP/HTTPS administrative interface as a workaround.

External references