{"cveID":"CVE-2025-32756","vendorProject":"Fortinet","product":"Multiple Products","vulnerabilityName":"Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability","dateAdded":"2025-05-14","shortDescription":"Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-06-04","knownRansomwareCampaignUse":"Unknown","notes":"https://fortiguard.fortinet.com/psirt/FG-IR-25-254 ; https://nvd.nist.gov/vuln/detail/CVE-2025-32756","cwes":["CWE-124"],"year":2025,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2025-32756","technique":"T1133","technique_name_at_mapping":"External Remote Services","mapping_type":"exploitation_technique","capability_group":"buffer_overflow","comments":"Attackers use a Python script (publicly available or custom) to send a malformed POST request, triggering a buffer overflow. From there, they execute remote code and malicious payloads (i.e. malware), harvest credentials, move laterally over the network, erase logs to avoid detection, and exfiltrate data over C2.","references":["https://www.centripetal.ai/threat-research/proof-of-concept-exploit-observed-for-critical-zero-day"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-32756","technique":"T1003","technique_name_at_mapping":"OS Credential Dumping","mapping_type":"secondary_impact","capability_group":"buffer_overflow","comments":"Attackers use a Python script (publicly available or custom) to send a malformed POST request, triggering a buffer overflow. From there, they execute remote code and malicious payloads (i.e. malware), harvest credentials, move laterally over the network by scanning for other devices, erase logs to avoid detection, and exfiltrate data over C2.","references":["https://www.centripetal.ai/threat-research/proof-of-concept-exploit-observed-for-critical-zero-day"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-32756","technique":"T1041","technique_name_at_mapping":"Exfiltration Over C2 Channel","mapping_type":"secondary_impact","capability_group":"buffer_overflow","comments":"Attackers use a Python script (publicly available or custom) to send a malformed POST request, triggering a buffer overflow. From there, they execute remote code and malicious payloads (i.e. malware), harvest credentials, move laterally over the network by scanning for other devices, erase logs to avoid detection, and exfiltrate data over C2.","references":["https://www.centripetal.ai/threat-research/proof-of-concept-exploit-observed-for-critical-zero-day"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-32756","technique":"T1046","technique_name_at_mapping":"Network Service Discovery","mapping_type":"secondary_impact","capability_group":"buffer_overflow","comments":"Attackers use a Python script (publicly available or custom) to send a malformed POST request, triggering a buffer overflow. From there, they execute remote code and malicious payloads (i.e. malware), harvest credentials, move laterally over the network by scanning for other devices, erase logs to avoid detection, and exfiltrate data over C2.","references":["https://www.centripetal.ai/threat-research/proof-of-concept-exploit-observed-for-critical-zero-day"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-32756","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"buffer_overflow","comments":"Attackers use a Python script (publicly available or custom) to send a malformed POST request, triggering a buffer overflow. From there, they execute remote code and malicious payloads (i.e. malware), harvest credentials, move laterally over the network, erase logs to avoid detection, and exfiltrate data over C2.","references":["https://www.centripetal.ai/threat-research/proof-of-concept-exploit-observed-for-critical-zero-day"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-32756","technique":"T1070.004","technique_name_at_mapping":"File Deletion","mapping_type":"secondary_impact","capability_group":"buffer_overflow","comments":"Attackers use a Python script (publicly available or custom) to send a malformed POST request, triggering a buffer overflow. From there, they execute remote code and malicious payloads (i.e. malware), harvest credentials, move laterally over the network by scanning for other devices, erase logs to avoid detection, and exfiltrate data over C2.","references":["https://www.centripetal.ai/threat-research/proof-of-concept-exploit-observed-for-critical-zero-day"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-32756","technique":"T1608.001","technique_name_at_mapping":"Upload Malware","mapping_type":"secondary_impact","capability_group":"buffer_overflow","comments":"Attackers use a Python script (publicly available or custom) to send a malformed POST request, triggering a buffer overflow. From there, they execute remote code and malicious payloads (i.e. malware), harvest credentials, move laterally over the network, erase logs to avoid detection, and exfiltrate data over C2.","references":["https://www.centripetal.ai/threat-research/proof-of-concept-exploit-observed-for-critical-zero-day"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"OS Credential Dumping","name_at_mapping":"OS Credential Dumping","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":37,"has_detection_strategy":true},{"id":"T1041","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exfiltration Over C2 Channel","name_at_mapping":"Exfiltration Over C2 Channel","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":5,"has_detection_strategy":true},{"id":"T1046","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Network Service Discovery","name_at_mapping":"Network Service Discovery","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":20,"has_detection_strategy":true},{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1070.004","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"File Deletion","name_at_mapping":"File Deletion","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":15,"has_detection_strategy":true},{"id":"T1133","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"External Remote Services","name_at_mapping":"External Remote Services","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":20,"has_detection_strategy":true},{"id":"T1608.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Upload Malware","name_at_mapping":"Upload Malware","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":0,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}