Stack-based buffer overflow on fortitoken import feature

Summary

A stack-based buffer overflow vulnerability [CWE-121] in FortiOS and FortiProxy may allow an authenticated attacker to achieve arbitrary code execution via certain CLI commands.

Version Affected Solution
FortiOS 7.6 Not affected Not Applicable
FortiOS 7.4 7.4.0 through 7.4.1 Upgrade to 7.4.2 or above
FortiOS 7.2 7.2.0 through 7.2.11 Upgrade to 7.2.12 or above
FortiOS 7.0 7.0 all versions Migrate to a fixed release
FortiOS 6.4 6.4.6 through 6.4.16 Migrate to a fixed release
FortiOS 6.2 6.2.9 through 6.2.17 Migrate to a fixed release
FortiOS 6.0 6.0.13 through 6.0.18 Migrate to a fixed release
FortiProxy 7.6 Not affected Not Applicable
FortiProxy 7.4 7.4.0 through 7.4.7 Upgrade to 7.4.8 or above
FortiProxy 7.2 7.2 all versions Migrate to a fixed release
FortiProxy 7.0 7.0 all versions Migrate to a fixed release
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

Timeline

2025-10-14: Initial publication