Target Industry
Indiscriminate, opportunistic targeting.
Overview
A zero-day exploited, tracked as CVE-2025-32756, has been fixed by Fortinet. This critical stack-based buffer overflow vulnerability is affecting Fortinet’s FortiVoice, a communication platform that combines calling, conferencing, chat, fax, and mobility features into one system. The vulnerability, with a base score of 9.8, allows remote unauthenticated threat actors to execute arbitrary code.
Impact
CVE-2025-32756 allows for remote, unauthenticated threat actors to execute arbitrary code, potentially leading to data breaches, service disruptions, and full system compromise.
Exploitation
Threat actors exploit this vulnerability by HTTP requests containing a specially crafted hash cookie to the vulnerable system. The crafted request triggers a buffer overflow in the system’s software. The overflow allows the threat actors to execute their malicious code.
Affected Products
The table below shows the products affected by CVE-2025-32756:
| Product | Affected |
| FortiCamera | 2.1.0 – 2.1.3 2.0 all versions 1.1 all versions |
| FortiMail | 7.6.0 – 7.6.2 7.4.0 – 7.4.4 7.2.0 – 7.2.7 7.0.0 – 7.0.8 |
| FortiNDR | 7.6.0 7.4.0 – 7.4.7 7.2.0 – 7.2.4 7.1 all versions 7.0.0 – 7.0.6 1.5 all versions 1.4 all versions 1.3 all versions 1.2 all versions 1.1 all versions |
| FortiRecorder | 7.2.0 – 7.2.3 7.0.0 – 7.0.5 6.4.0 – 6.4.5 |
| FortiVoice | 7.2.0 7.0.0 – 7.0.6 6.4.0 – 6.4.10 |
Indicators of Compromise
Below are hash values noted as Indicators of compromise (IoCs). For further IoCs please visit the FortiGuard Labs website.
| IoC Type | IoC Value |
| MD5 Hash | ebce43017d2cb316ea45e08374de7315 |
| MD5 Hash | 2c8834a52faee8d87cff7cd09c4fb946 |
| MD5 Hash | 364929c45703a84347064e2d5de45bcd |
| MD5 Hash | 4410352e110f82eabc0bf160bec41d21 |
| MD5 Hash | 489821c38f429a21e1ea821f8460e590 |
Containment, Mitigations & Remediations
To mitigate the CVE-2025-32756 vulnerability in Fortinet products it is highly recommended to:
- Ensure that all affected products are updated to the latest versions that include the security patches
- Disable HTTP/HTTPS Administrative Interface, if you cannot update immediately, disable the HTTP/HTTPS administrative interface on vulnerable devices
- Regularly check for IoCs such as unusual log entries, unexpected files, and modified settings
- Conduct network scans to identify and isolate any compromised devices
- Review and harden system configurations to minimise exposure to potential exploits.
Further Information













