PoC Published For Fortinet 0-Day Vulnerability That Being Exploited in the Wild
## Fortinet Zero-Day Vulnerability: Technical Overview
Fortinet Zero-Day Vulnerability: Technical Overview
Security researchers have released a detailed proof-of-concept (PoC) analysis for a critical zero-day vulnerability affecting multiple Fortinet products. This vulnerability, tracked as CVE-2025-32756, poses a significant security risk with a CVSS score of 9.6 out of 10.
The vulnerability is a stack-based buffer overflow in the administrative API. It allows remote unauthenticated attackers to execute arbitrary code through specially crafted HTTP requests.
The flaw impacts five major Fortinet product lines: FortiVoice, FortiMail, FortiNDR, FortiRecorder, and FortiCamera across multiple versions.
Vulnerability Under Active Exploitation
Technical analysis by Horizon3 security researchers indicates that the vulnerability arises from improper bounds checking during the processing of APSCOOKIE values in the cookieval_unwrap() function within the libhttputil.so library. Patched versions include size checks that limit AuthHash values, while vulnerable versions allow attackers to overflow a 16-byte output buffer and overwrite critical stack values, including the return address.
Fortinet has confirmed active exploitation of this vulnerability, particularly targeting FortiVoice unified communication systems. The exploitation was discovered through observed threat activities such as network scanning, credential harvesting, and log file manipulation.
Security researchers have released a detailed proof-of-concept (PoC) analysis for a critical zero-day vulnerability affecting multiple Fortinet products.
Fortinet's indicators of compromise (IoCs) reveal that attackers have been conducting device network scans, erasing system crash logs, and enabling 'fcgi debugging' to capture authentication attempts, including SSH logins. Threat actors have also deployed malware and established cron jobs for ongoing credential theft.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-32756 to its Known Exploited Vulnerabilities (KEV) catalog on May 14, 2025. This designation mandates federal agencies to remediate the vulnerability by June 4, 2025, emphasizing the urgency of the threat.
Security experts strongly recommend immediate upgrades to fixed versions across all affected products. For organizations unable to patch immediately, Fortinet provides a workaround involving the disabling of the HTTP/HTTPS administrative interface.
FortiVoice systems should upgrade to versions 7.2.1, 7.0.7, or 6.4.11, depending on the current branch. FortiMail requires updates to 7.6.3, 7.4.5, 7.2.8, or 7.0.9.
This is the eighteenth Fortinet vulnerability added to CISA's KEV list, illustrating the ongoing targeting of Fortinet products by threat actors. The combination of active exploitation, technical PoC availability, and the critical nature of affected enterprise infrastructure creates an urgent security situation requiring immediate attention from organizations using these products.
Given the ease of exploitation and availability of technical details, security professionals expect additional threat actors may begin targeting vulnerable systems in the near future.
Based on reporting by Cyber Security News.
