CVE-2025-57740: Authenticated Heap Overflow in SSL-VPN bookmarks
An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions RDP bookmark connection may allow an authenticated user to execute unauthorized code via crafted requests.
Other sources
An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS, FortiPAM and FortiProxy RDP bookmark connection may allow an authenticated user to execute unauthorized code via crafted requests.
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.2.11 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.8 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.3 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.4.3 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.5.1 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.4 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.3 - Upgrade
Upgrade
FortiSASE-Sovereignto a version that resolves this vulnerability.Fixed in 25.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57740?
CVE-2025-57740 is classified as a high-severity vulnerability due to the potential for a heap-based buffer overflow.
How do I fix CVE-2025-57740?
To resolve CVE-2025-57740, upgrade to the latest versions of FortiOS, FortiPAM, or FortiProxy as specified in the vendor's advisory.
What versions are affected by CVE-2025-57740?
CVE-2025-57740 affects FortiOS versions 7.6.2 and below, FortiPAM versions 1.5.0 and below, among others listed in the vulnerability details.
Can CVE-2025-57740 lead to remote code execution?
Yes, CVE-2025-57740 can potentially allow remote code execution due to the nature of the heap-based buffer overflow.
Is there a public exploit available for CVE-2025-57740?
As of now, there are no confirmed public exploits for CVE-2025-57740, but organizations should still take precautionary measures.