CVE-2025-24477: Heap-based buffer overflow in cw_stad daemon
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS cwstad daemon may allow an authenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Other sources
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its privileges via a specially crafted CLI command
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24477?
CVE-2025-24477 is classified as a critical severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2025-24477?
To mitigate CVE-2025-24477, upgrade FortiOS to version 7.6.3, 7.4.8, or 7.2.12 or later.
What type of vulnerability is CVE-2025-24477?
CVE-2025-24477 is a heap-based buffer overflow vulnerability affecting FortiOS.
Who is affected by CVE-2025-24477?
Authenticated users of FortiOS versions prior to the remedial versions are at risk from CVE-2025-24477.
What can an attacker do with CVE-2025-24477?
An attacker can exploit CVE-2025-24477 to execute arbitrary code or commands on vulnerable instances of FortiOS.