CVE-2025-43892
Modified
Modified - Updated After Analysis
Buffer Over-Read in Fortinet FortiOS
Vulnerability report for CVE-2025-43892, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-14
Last updated on: 2026-07-16
Assigner: Fortinet, Inc.
Description
Description
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortios | From 7.4.0 (inc) to 7.4.8 (inc) |
| fortinet | fortiproxy | From 7.2.0 (inc) to 7.2.15 (inc) |
| fortinet | fortios | From 7.2.0 (inc) to 7.2.13 (inc) |
| fortinet | fortios | From 7.6.0 (inc) to 7.6.2 (inc) |
| fortinet | fortiproxy | From 7.4.0 (inc) to 7.4.13 (inc) |
| fortinet | fortiproxy | From 7.6.0 (inc) to 7.6.5 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-126 | The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer. |