Authenticated CLI Commands Buffer Overflow

Summary

A buffer overflow vulnerability [CWE-120] in FortiExtender json_cli may allow an authenticated user to execute arbitrary code or commands via crafted CLI commands.

Version Affected Solution
FortiExtender 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.3 or above
FortiExtender 7.4 7.4.0 through 7.4.6 Upgrade to 7.4.8 or above
FortiExtender 7.2 7.2 all versions Migrate to a fixed release
FortiExtender 7.0 7.0 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by David Maciejak of the Fortinet product security team

Timeline

2025-11-18: Initial publication