Cyber Resilience

CVE-2025-25248

MediumUpdated

Published: 12 August 2025

Published
12 August 2025
Modified
09 June 2026
KEV Added
Patch
CVSS Score v3.1 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0023 46.5th percentile
Risk Priority 11 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-25248 is a medium-severity Integer Overflow or Wraparound (CWE-190) vulnerability in Fortinet Fortios. Its CVSS base score is 5.3 (Medium).

Operationally, ranked at the 46.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0…

more

all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions SSL-VPN RDP and VNC bookmarks may allow an authenticated user to affect the device SSL-VPN availability via crafted requests.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

fortinet
fortios
6.4.0 — 7.2.11 · 7.4.0 — 7.4.8 · 7.6.0 — 7.6.3
fortinet
fortipam
1.5.0 · 1.0.0 — 1.4.3
fortinet
fortiproxy
2.0.0 — 7.4.4 · 7.6.0 — 7.6.3

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References