Fortinet has addressed a critical security vulnerability (CVE-2025-32756) that was actively exploited as a zero-day targeting FortiVoice enterprise phone systems. The flaw, rated with a severe CVSS score of 9.6 out of 10.0, affects multiple Fortinet products.
The vulnerability is a stack-based overflow (CWE-121) that allows remote unauthenticated attackers to execute arbitrary code or commands through crafted HTTP requests. Fortinet confirmed exploitation against FortiVoice systems, noting that attackers performed network scans, erased system crash logs, and enabled fcgi debugging to capture credentials from the system or SSH login attempts.
## Affected Products and Recommended Updates
– **FortiCamera**: Versions 1.1, 2.0 require migration; version 2.1.x needs upgrade to 2.1.4+
– **FortiMail**: Versions 7.0.x, 7.2.x, 7.4.x, and 7.6.x require specific upgrades
– **FortiNDR**: Multiple versions affected, with specific upgrade paths recommended
– **FortiRecorder**: Versions 6.4.x, 7.0.x, and 7.2.x need upgrades
– **FortiVoice**: Versions 6.4.x, 7.0.x, and 7.2.x require immediate updates
Fortinet’s product security team discovered the vulnerability after detecting suspicious activity from several IP addresses (198.105.127.124, 43.228.217.173, 43.228.217.82, 156.236.76.90, 218.187.69.244, and 218.187.69.59).
Users are strongly advised to apply the necessary patches immediately. If patching isn’t immediately possible, disabling the HTTP/HTTPS administrative interface is recommended as a temporary mitigation measure.
