SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2025-43892

MEDIUM · CVSS 4.3 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Fortinet FortiOS versions 6.4 through 7.6.3 are vulnerable to a buffer over-read issue that could allow authenticated remote attackers to access sensitive portions of device memory through specially crafted requests. This vulnerability poses a medium risk, as it could lead to information disclosure, potentially exposing sensitive data. Organizations using affected versions of FortiOS should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2025-43892
Severity
MEDIUM
CVSS
4.3
EPSS
0.34%
Fortinet FortiOS

Original NVD Description

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.

Related CVEs

Other vulnerabilities affecting the same vendor(s)