CVE-2025-43892: Buffer overread in authd and wad daemon
A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
Other sources
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiSASEto a version that resolves this vulnerability.Fixed in 25.4.b - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.9 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.4 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.14 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.6
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43892?
The severity of CVE-2025-43892 is medium with a CVSS score of 4.3.
How do I fix CVE-2025-43892?
To fix CVE-2025-43892, upgrade to the patched versions of FortiOS or FortiProxy provided by Fortinet.
What systems are affected by CVE-2025-43892?
CVE-2025-43892 affects Fortinet FortiOS versions 7.6.0 through 7.6, as well as FortiProxy.
What type of vulnerability is CVE-2025-43892?
CVE-2025-43892 is classified as a buffer over-read vulnerability.
Who can exploit CVE-2025-43892?
An authenticated remote attacker can exploit CVE-2025-43892 by submitting a specially crafted request.