CVE-2025-32756 is a stack-based buffer overflow in the portal and administrative HTTP interfaces of Fortinet FortiCamera, FortiMail, FortiNDR, FortiRecorder, and FortiVoice. Improper bounds checking during HTTP request processing allows a remote unauthenticated attacker to trigger memory corruption and execute arbitrary code or commands by sending requests containing a specially crafted hash cookie. Affected versions include FortiCamera 2.1.0–2.1.3 and all 2.0 and 1.1 releases; FortiMail 7.6.0–7.6.2, 7.4.0–7.4.4, 7.2.0–7.2.7, and 7.0.0–7.0.8; FortiNDR 7.6.0, 7.4.0–7.4.7, 7.2.0–7.2.4, and 7.0.0–7.0.6; FortiRecorder 7.2.0–7.2.3, 7.0.0–7.0.5, and 6.4.0–6.4.5; and FortiVoice 7.2.0, 7.0.0–7.0.6, and 6.4.0–6.4.10. Older FortiNDR 7.1 and 1.1–1.5 branches are also identified as affected. Exploitation in the wild has been confirmed against FortiVoice.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-32756, a stack-based buffer overflow vulnerability affecting multiple Fortinet products (FortiVoice, FortiMail, FortiNDR, FortiRecorder, FortiCamera) across several versions. The exploit is implemented in a single Python script (CVE-2025-32756.py), which constructs and sends specially crafted HTTP POST requests to the /remote/hostcheck_validate endpoint of a target device. The payload is designed to overflow a stack buffer by abusing the enc parameter, potentially leading to a crash, denial of service, or remote code execution. The script also interacts with the /remote/info endpoint to retrieve a salt value required for payload construction. The repository includes a README.md with detailed vulnerability, usage, and mitigation information, and a requirements.txt listing Python dependencies. The exploit is a PoC and does not include a post-exploitation payload; its primary purpose is to demonstrate the existence of the vulnerability.
This repository consists of a single configuration file (config.json) that defines the parameters for a remote exploit targeting a service at 180.21.21.21:443 over HTTPS, specifically the /remote/login endpoint. The exploit is designed for an amd64, little-endian target with ASLR and stack canary mitigations disabled, but DEP/NX enabled. The attack uses a ROP chain to execute /bin/sh, opening a bind shell on port 5555. The exploit is delivered via a specially crafted HTTP GET request with the payload in a cookie. Post-exploitation, the exploit can execute commands on the target, such as writing the output of 'id' to /pwned.html. The repository does not contain code, only configuration, and is likely intended to be used with an external exploit framework or script that interprets this configuration.
This repository provides a Python proof-of-concept (PoC) exploit for CVE-2025-32756, a critical stack-based buffer overflow vulnerability in several Fortinet products (FortiVoice, FortiMail, FortiNDR, FortiRecorder, FortiCamera). The exploit targets the /remote/hostcheck_validate endpoint, abusing improper bounds checking in the processing of the 'enc' parameter. The main script, 'fortinet_cve_2025_32756_poc.py', constructs a specially crafted payload using a salt (retrieved from /remote/info) and a seed, then sends two HTTP POST requests to the vulnerable endpoint to trigger the overflow. The PoC demonstrates the vulnerability but does not deliver a shell or custom code execution payload. The repository also includes a README.md with detailed usage instructions, affected product versions, and mitigation advice, as well as a requirements.txt listing Python dependencies. The exploit is unauthenticated and works over HTTPS, making it a remote, network-based attack. The code is structured for clarity and research purposes, with debug options and clear separation of payload construction and delivery logic.
This repository provides a Python proof-of-concept (PoC) exploit for CVE-2025-32756, a critical unauthenticated stack-based buffer overflow vulnerability in several Fortinet products (FortiVoice, FortiMail, FortiNDR, FortiRecorder, FortiCamera). The main exploit script, 'fortinet_cve_2025_32756_poc.py', allows users to scan for vulnerable devices and attempt exploitation by sending a specially crafted HTTP POST request to the '/remote/hostcheck_validate' endpoint with a malformed 'enc' parameter. The script demonstrates the vulnerability by triggering the overflow and modifying a single byte in memory, but does not execute arbitrary code or provide shell access. The repository also includes a README with detailed usage instructions and mitigation advice, a requirements.txt for dependencies, and a .gitignore. The exploit is network-based, targeting HTTPS services on the affected Fortinet devices. The code is structured to support both single-target exploitation and multi-target scanning, with options for IP ranges and output to CSV. This PoC is intended for research and educational purposes only and does not weaponize the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
116 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An earlier, independent Fortinet zero-day affecting FortiMail and FortiVoice, with confirmed exploitation against FortiVoice. It is mentioned for comparison and to emphasize that its affected versions, indicators, and remediation differ from CVE-2026-104286. Its technical root cause is not specified in this content.
A previously reported, separate Fortinet zero-day vulnerability mentioned only for comparison with the primary FortiMail vulnerability.
A 2025 vulnerability listed among those incorporated into RondoDox exploitation activity after public disclosure.
A critical stack-based overflow vulnerability in Fortinet products (including FortiVoice) enabling remote unauthenticated code execution; exploited as a zero-day.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.