VDB

GCVE-110-NCSC-2025-355

GCVE-110-NCSC-2025-355
Advisory PublishedCVSS 6.7/10
Vulnetix · Advisory published November 7, 2025
A stack-based buffer overflow vulnerability in Fortinet FortiOS and FortiProxy allows authenticated attackers to execute arbitrary code through specially crafted CLI commands.

Weaknesses (CWE)

CWE-121Stack-based Buffer OverflowCWE-297Improper Validation of Certificate with Host MismatchCWE-358Improperly Implemented Security Check for StandardCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-532Insertion of Sensitive Information into Log FileCWE-601URL Redirection to Untrusted Site ('Open Redirect')CWE-285Improper Authorization

Risk Scores

CVSS 3.1
6.7/10
Medium · CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:X

Affected Products

VendorProductVersionsPlatforms
Fortinetvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›