Skip to content
Threat Feed
critical advisory

Critical RCE Vulnerability in Fortinet Products via AuthHash Cookie (CVE-2025-32756)

A critical unauthenticated stack-based buffer overflow vulnerability, tracked as CVE-2025-32756, affects multiple Fortinet products and can be triggered via a crafted 'enc' parameter in the 'AuthHash' cookie.

CVE search metadata

CVE search record: CVE-2025-32756. Severity: critical. CVSS: 9.8. EPSS: 29.81%. KEV: no. Product: FortiMail (< 7.0.9, 7.2.8, 7.4.5, 7.6.3), FortiNDR (< 7.0.7, 7.2.5, 7.4.8, 7.6.1), FortiRecorder (< 6.4.6, 7.0.6, 7.2.4), FortiVoice (< 6.4.11, 7.0.7, 7.2.1), FortiCamera (< 2.1.4). Brief: Critical RCE Vulnerability in Fortinet Products via AuthHash Cookie (CVE-2025-32756). Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2025-32756-fortinet-rce/

CVE-2025-32756 is a critical stack-based buffer overflow vulnerability affecting a wide range of Fortinet products, including FortiMail, FortiNDR, FortiRecorder, FortiVoice, and FortiCamera. The flaw exists in the handling of the 'enc' parameter within the 'AuthHash' cookie when processed by the '/remote/hostcheck_validate' endpoint. Because this endpoint is reachable without authentication, remote attackers can trigger the buffer overflow by sending specifically crafted HTTP requests. Public proof-of-concept exploit code has been released, allowing for the discovery and exploitation of vulnerable systems. Defenders should prioritize patching or restricting access to the vulnerable endpoint immediately, as this vulnerability carries a CVSS score of 9.8.

Attack Chain

  1. Attacker performs reconnaissance or network scanning to identify reachable Fortinet devices.
  2. Attacker targets the '/remote/hostcheck_validate' URI on the discovered Fortinet appliance.
  3. Attacker crafts a malicious HTTP request containing a specially formed 'AuthHash' cookie.
  4. Attacker inserts a payload into the 'enc' parameter within the cookie, designed to exceed the allocated stack buffer.
  5. The target Fortinet appliance processes the cookie, triggering the buffer overflow condition during memory handling.
  6. Attacker potentially gains control of the instruction pointer to achieve arbitrary code execution.

Impact

Successful exploitation of CVE-2025-32756 results in unauthenticated remote code execution, granting attackers the ability to compromise the confidentiality, integrity, and availability of the affected Fortinet appliances. These devices are often positioned at the network perimeter, and their compromise could facilitate deeper network penetration or interception of organizational traffic.

Recommendation

  • Upgrade FortiMail to 7.0.9, 7.2.8, 7.4.5, 7.6.3 or later.
  • Upgrade FortiNDR to 7.0.7, 7.2.5, 7.4.8, 7.6.1 or later.
  • Upgrade FortiRecorder to 6.4.6, 7.0.6, 7.2.4 or later.
  • Upgrade FortiVoice to 6.4.11, 7.0.7, 7.2.1 or later.
  • Upgrade FortiCamera to 2.1.4 or later.
  • Monitor web server access logs for anomalous POST or GET requests targeting the '/remote/hostcheck_validate' path, specifically looking for unusually long or malformed 'AuthHash' cookie strings.
  • Implement access controls to restrict exposure of administrative or authentication-related endpoints to untrusted networks.

Immediate actions

Patch affected Fortinet appliances to the versions listed in the Recommendation section.

IT Operations 24h

Threat Hunt

Search logs for requests to /remote/hostcheck_validate originating from external IP addresses.

T1190 high high confidence hunt now

Data: Web server logs

Mitigations

Restrict external access to Fortinet appliances if patching cannot be performed immediately.

immediate IT Operations

CVE-2025-32756

Detection coverage 1

Detects CVE-2025-32756 Exploitation - Unauthorized Request to hostcheck_validate

high

Detects exploitation attempts against CVE-2025-32756 by monitoring for requests to the vulnerable endpoint with suspicious cookie parameters

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →