2026年10月2日星期五

Fortinet Products Remote Code Execution Vulnerability

Fortinet Products Remote Code Execution Vulnerability

Release Date: 2 Oct 2026

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and data manipulation on the targeted system.

 

Note:

CVE-2025-25249 is being exploited in the wild. An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') and Improper Neutralization of NULL Byte or NULL Character vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Hence, the risk level of this vulnerability is rated as Extremely High Risk.


Impact

  • Remote Code Execution
  • Data Manipulation

System / Technologies affected

FortiMail

  • FortiMail 8.0.0 through 8.0.1
  • FortiMail 7.6.0 through 7.6.6
  • FortiMail 7.4.0 through 7.4.8
  • FortiMail 7.2.0 through 7.2.9

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

 


沒有留言:

發佈留言

Fortinet 產品遠端執行程式碼漏洞

Fortinet 產品遠端執行程式碼漏洞 發佈日期 : 2026 年 10 月 02 日 於 Fortinet 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及資料篡改。   注意: CVE-2025-25249 正在被廣泛利用...