CVE-2025-54820Disclosure(fortinet / fortimanager)

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch fortinet fortimanager systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortimanager

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-03-10); latest day: 2
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
fortimanager

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-03-10: 2Mentions · 2026-03-11: 2Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-03-18: 2PoC Mentioned / Linked · 2026-03-11: 1Patch / Workaround · 2026-03-10: 2Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-11: 2Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-18: 203-1003-1103-1203-1303-18
Signal classification3 categories
Disclosure
450.0%
Patch
337.5%
General
112.5%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-102
Patch2
2026-03-112
Disclosure1Patch1
2026-03-121
Disclosure1
2026-03-131
Disclosure1
2026-03-182
Disclosure1General1
Full discourse8 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    2026年3月ぱっちちゅーずーでー ▼Microsoft 2026 年 3 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/03/202603-security-update CVE-2026-26127 .NET のサービス拒否の脆弱性 CVE-2026-21262 SQL サーバーの特権の昇格の脆弱性 ▼SAP SAP Security Patch Day - March 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/march-2026.html CVE-2019-17571 SAP Quotation Management Insurance アプリケーション (FS-QUO) におけるコードインジェクションの脆弱性 CVE-2026-27685 SAP NetWeaver Enterprise Portal 管理における安全でないデシリアライゼーション ▼Ivanti(critical系はなし) March 2026 Security Update https://www.ivanti.com/blog/march-2026-security-update CVE-2026-3483 バージョン 2026.1.1 より前の Ivanti DSM で公開されている危険な方法により、ローカルで認証された攻撃者が権限を昇格できる可能性 ▼Fortinet(critical系はなし) https://fortiguard.fortinet.com/psirt CVE-2026-22627 LLDP OUIフィールドのバッファオーバーフロー CVE-2025-54820 fgtupdates サービスによるバッファオーバーフロー ▼Adobe https://helpx.adobe.com/security.html

    Post summary

    The text announces vendor security updates for several CVEs, specifying the vulnerability types and providing links to patch advisories.

    100201.1K
    11.4K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    FortiManager fgtupdates の脆弱性 CVE-2025-54820 が FIX:悪意のコマンド実行の恐れ https://iototsecnews.jp/2026/03/10/fortinet-fortimanager-fgtupdates-vulnerability-allows-attackers-to-execute-malicious-commands/ この脆弱性 CVE-2025-54820 は、 FortiManager の fgtupdates サービスにおけるスタックバッファ・オーバーフローに起因します。この問題は、外部からのリクエストを処理する際に、メモリ上のスタック領域に用意されたサイズを超えて、データが書き込まれることで発生します。この現象により、プログラムの制御が奪われ、未認証のリモート攻撃者が不正なコマンドを実行できる状態になってしまいます。幸いなことに、スタック保護メカニズムという防御策が攻撃の難易度を高めていますが、特定のサービスが有効化されている場合には依然としてリスクが残ります。ご利用のチームは、ご注意ください。 #CVE202554820 #FortiManagerfgtupdates #Fortinet #Vulnerability

    Post summary

    The article announces a stack buffer overflow vulnerability (CVE‑2025‑54820) in FortiManager’s fgtupdates service that could allow unauthenticated remote command execution, but it provides no PoC, tool, patch, or evidence of active exploitation.

    01000191
    484 followersView on X
  • BaroPAM@rokmc_sns
    Disclosure

    인증 없이 관리자 권한 강탈... 포티매니저 취약점 공개, 온프레미스 기업 ‘비상’ 포티매니저 ‘fgtupdates’ 서비스 내 스택 기반 버퍼 오버플로 취약점(CVE-2025-54820) 발견 인증 없는 원격 공격으로 사내 연결된 하위 보안 장비 전체 통제권 탈취 가능성 고조 https://www.boannews.com/media/view.asp?idx=142601

    Post summary

    The FortiManager "fgtupdates" service contains a stack-based buffer overflow (CVE‑2025‑54820) that could allow unauthenticated remote attackers to potentially hijack all connected subordinate security devices.

    01000147
    1.7K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Fortinet's FortiManager fgtupdates service vulnerability (CVE-2025-54820) allows remote code execution. Upgrade now to secure your systems! Link: https://thedailytechfeed.com/fortinet-fortimanager-vulnerability-allows-remote-code-execution-users-urged-to-patch-immediately/ #Security #Vulnerability #Exploit #Patch #Update #Software #Network #Technology #Cyber #Protection #Threat #Data #IT #Risk #Firewall #Safety #Hacking #Defense #System #FortiManager

    Post summary

    The post highlights a remote code execution flaw in FortiManager (CVE‑2025‑54820) and urges users to apply the latest patch immediately.

    0001028
    260 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-54820 A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 … https://www.cve.org/CVERecord?id=CVE-2025-54820

    Post summary

    The post provides a brief CVE record for CVE-2025-54820, noting a stack-based buffer overflow in various FortiManager versions, but offers no additional information on PoC, exploitation, or patching.

    00000207
    56.7K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 FortiManager, Stack Buffer Overflow, #CVE-2025-54820 (High) https://dailycve.com/fortimanager-stack-buffer-overflow-cve-2025-54820-high/

    Post summary

    The tweet announces a high‑severity stack buffer overflow vulnerability (CVE-2025-54820) in FortiManager, but provides no additional details on exploitation, PoC, or remediation.

    0000090
    168 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚠️ CVE-2025-54820: Fortinet (CVSS: 7.0)... Stack smashing FortiManager across 3+ major versions with unauthenticated RCE - ASLR/DEP bypass required but when has t... https://zerodaysignal.com/vulnerability/CVE-2025-54820 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces the CVE-2025-54820 vulnerability in Fortinet FortiManager, detailing stack smashing and unauthenticated RCE across multiple versions, and provides a link for more information.

    00000180
    142 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fortinet issues security advisory for 11 flaws in FortiManager, FortiAnalyzer, FortiSwitchAXFixed, FortiSandbox, incl. CVE-2025-54820 allowing remote unauth command exec via fgtupdates. Patch now. #Vulnerability https://threatcluster.io/cluster/fortinet-issues-security-advisory-for-critical-vulnerabiliti-8ed32d0a

    Post summary

    The tweet announces a Fortinet security advisory covering 11 vulnerabilities, including CVE-2025‑54820, and urges users to apply the available patch.

    00000122
    99 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortimanager---

Explore more