CVE-2025-46776: Authenticated CLI Commands Buffer Overflow
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to execute arbitrary code or commands via crafted CLI commands.
Other sources
A buffer overflow vulnerability [CWE-120] in FortiExtender jsoncli may allow an authenticated user to execute arbitrary code or commands via crafted CLI commands.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46776?
CVE-2025-46776 is considered a high severity vulnerability due to the potential for authenticated users to execute arbitrary code.
How do I fix CVE-2025-46776?
To fix CVE-2025-46776, upgrade FortiExtender to version 7.6.3 or 7.4.8 depending on your current version.
Which FortiExtender versions are affected by CVE-2025-46776?
CVE-2025-46776 affects FortiExtender versions 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, all versions of 7.2, and all versions of 7.0.
Is there a workaround for CVE-2025-46776?
Currently, there are no known workarounds for CVE-2025-46776, making an upgrade the only effective solution.
What are the consequences of not addressing CVE-2025-46776?
Failing to address CVE-2025-46776 may allow an authenticated user to execute arbitrary code, leading to potential system compromise.