• News/
  • https://www.bleepingcomputer.com/news/security/fortinet-fixes-critical-zero-day-exploited-in-fortivoice-attacks/

Fortinet fixes critical zero-day exploited in FortiVoice attacks

BleepingComputer
·
Sergiu Gatlan
·
Published May 13, 2025
·
Updated

Fortinet released security updates to patch a critical remote code execution vulnerability exploited as a zero-day in attacks targeting FortiVoice enterprise phone systems. The security flaw is a stack-based overflow vulnerability tracked as CVE-2025-32756 that also impacts FortiMail, FortiNDR, FortiRecorder, and FortiCamera. As the company explains in a security advisory issued on Tuesday, successful exploitation can allow remote unauthenticated attackers to execute arbitrary code or commands via maliciously crafted HTTP requests. Fortinet's Product Security Team discovered CVE-2025-32756 based on attackers' activity, including network scans, system crashlogs deletion to cover their tracks, and 'fcgi debugging' being toggled on to log credentials from the system or SSH login attempts. As detailed in today's security advisory, the threat actors have launched attacks from half a dozen IP addresses, including 198.105.127[.]124, 43.228.217[.]173, 43.228.217[.]82, 156.236.76[.]90, 218.187.69[.]244, and 218.187.69[.]59. Indicators of compromise spotted by Fortinet during the attacks' analysis include the 'fcgi debugging' setting (which isn't toggled on by default), enabled on compromised systems. To check if this setting is turned on on your system, you should see "general to-file ENABLED" after running the following command: diag debug application fcgi. While investigating these attacks, Fortinet has observed the threat actors deploying malware on hacked devices, adding cron job...

Read full article

Affected Software

10 affected components
Fortinet FortiVoice
Fortinet FortiMail
Fortinet FortiNDR
Fortinet FortiRecorder
Fortinet FortiCamera
Fortinet FortiVoice
Fortinet FortiMail
Fortinet FortiNDR
Fortinet FortiRecorder
Fortinet FortiCamera
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203