CVE-2025-54820 is a high-severity Stack-based Buffer Overflow vulnerability (CWE-121) impacting Fortinet FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.10, and all 6.4 versions. Rated 8.1 HIGH on the CVSS scale, this flaw allows a remote, unauthenticated attacker to execute unauthorized commands if a specific service is enabled, although successful exploitation requires bypassing stack protection. There is currently no evidence of active exploitation, public exploit code availability, or significant community discussion or media coverage for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.4.0, <= 6.4.15CPE match | cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* | ||
>= 7.2.0, <= 7.2.10CPE match | cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* | ||
>= 7.4.0, <= 7.4.2CPE match | cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* | ||
>= 6.4.0, < 7.2.11CPE matchmatch criteria | cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* | ||
>= 7.4.0, < 7.4.3CPE matchmatch criteria | cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
FG-IR-26-098 Buffer overflow via fgtupdates service
Mar 10, 2026FG-IR-26-098 Buffer overflow via fgtupdates service
Mar 10, 2026Buffer overflow via fgtupdates service
Mar 10, 2026FG-IR-26-098 Buffer overflow via fgtupdates service
Mar 10, 2026FG-IR-26-098 Buffer overflow via fgtupdates service
Mar 10, 2026