Cyber Resilience

CVE-2025-57740

HighUpdated

Published: 14 October 2025

Published
14 October 2025
Modified
09 June 2026
KEV Added
Patch
CVSS Score v3.1 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0006 19.6th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-57740 is a high-severity Heap-based Buffer Overflow (CWE-122) vulnerability in Fortinet Fortios. Its CVSS base score is 7.5 (High).

Operationally, ranked at the 19.6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1…

more

all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions RDP bookmark connection may allow an authenticated user to execute unauthorized code via crafted requests.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

fortinet
fortiproxy
7.0.0 — 7.4.4 · 7.6.0 — 7.6.3
fortinet
fortipam
1.5.0 · 1.0.0 — 1.4.3
fortinet
fortios
6.4.0 — 7.2.11 · 7.4.0 — 7.4.8 · 7.6.0 — 7.6.3

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References