Target Industry

Indiscriminate, opportunistic targeting.

Overview

A zero-day exploited, tracked as CVE-2025-32756, has been fixed by Fortinet. This critical stack-based buffer overflow vulnerability is affecting Fortinet’s FortiVoice, a communication platform that combines calling, conferencing, chat, fax, and mobility features into one system. The vulnerability, with a base score of 9.8, allows remote unauthenticated threat actors to execute arbitrary code. 

Impact

CVE-2025-32756 allows for remote, unauthenticated threat actors to execute arbitrary code, potentially leading to data breaches, service disruptions, and full system compromise.  

Exploitation

Threat actors exploit this vulnerability by HTTP requests containing a specially crafted hash cookie to the vulnerable system. The crafted request triggers a buffer overflow in the system’s software. The overflow allows the threat actors to execute their malicious code. 

Affected Products

The table below shows the products affected by CVE-2025-32756: 

 

Product Affected 
FortiCamera 2.1.0 – 2.1.3 

2.0 all versions 

1.1 all versions 

FortiMail 7.6.0 – 7.6.2 

7.4.0 – 7.4.4 

7.2.0 – 7.2.7 

7.0.0 – 7.0.8 

FortiNDR 7.6.0 

7.4.0 – 7.4.7 

7.2.0 – 7.2.4 

7.1 all versions 

7.0.0 – 7.0.6 

1.5 all versions 

1.4 all versions 

1.3 all versions 

1.2 all versions 

1.1 all versions 

FortiRecorder 7.2.0 – 7.2.3 

7.0.0 – 7.0.5 

6.4.0 – 6.4.5 

FortiVoice 7.2.0 

7.0.0 – 7.0.6 

6.4.0 – 6.4.10 

Indicators of Compromise

Below are hash values noted as Indicators of compromise (IoCs). For further IoCs please visit the FortiGuard Labs website. 

IoC Type IoC Value 
MD5 Hash ebce43017d2cb316ea45e08374de7315 
MD5 Hash 2c8834a52faee8d87cff7cd09c4fb946 
MD5 Hash 364929c45703a84347064e2d5de45bcd 
MD5 Hash 4410352e110f82eabc0bf160bec41d21 
MD5 Hash 489821c38f429a21e1ea821f8460e590 

 

Containment, Mitigations & Remediations

To mitigate the CVE-2025-32756 vulnerability in Fortinet products it is highly recommended to: 

  • Ensure that all affected products are updated to the latest versions that include the security patches 
  • Disable HTTP/HTTPS Administrative Interface, if you cannot update immediately, disable the HTTP/HTTPS administrative interface on vulnerable devices 
  • Regularly check for IoCs such as unusual log entries, unexpected files, and modified settings 
  • Conduct network scans to identify and isolate any compromised devices 
  • Review and harden system configurations to minimise exposure to potential exploits. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content