<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:fortinet:fortindr:7.1.1:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afortinetfortindr7.1.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 02:08:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afortinetfortindr7.1.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical RCE Vulnerability in Fortinet Products via AuthHash Cookie (CVE-2025-32756)</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2025-32756-fortinet-rce/</link><pubDate>Thu, 10 Sep 2026 02:08:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2025-32756-fortinet-rce/</guid><description>A critical unauthenticated stack-based buffer overflow vulnerability, tracked as CVE-2025-32756, affects multiple Fortinet products and can be triggered via a crafted 'enc' parameter in the 'AuthHash' cookie.</description><content:encoded><![CDATA[<p>CVE-2025-32756 is a critical stack-based buffer overflow vulnerability affecting a wide range of Fortinet products, including FortiMail, FortiNDR, FortiRecorder, FortiVoice, and FortiCamera. The flaw exists in the handling of the 'enc' parameter within the 'AuthHash' cookie when processed by the '/remote/hostcheck_validate' endpoint. Because this endpoint is reachable without authentication, remote attackers can trigger the buffer overflow by sending specifically crafted HTTP requests. Public proof-of-concept exploit code has been released, allowing for the discovery and exploitation of vulnerable systems. Defenders should prioritize patching or restricting access to the vulnerable endpoint immediately, as this vulnerability carries a CVSS score of 9.8.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance or network scanning to identify reachable Fortinet devices.</li>
<li>Attacker targets the '/remote/hostcheck_validate' URI on the discovered Fortinet appliance.</li>
<li>Attacker crafts a malicious HTTP request containing a specially formed 'AuthHash' cookie.</li>
<li>Attacker inserts a payload into the 'enc' parameter within the cookie, designed to exceed the allocated stack buffer.</li>
<li>The target Fortinet appliance processes the cookie, triggering the buffer overflow condition during memory handling.</li>
<li>Attacker potentially gains control of the instruction pointer to achieve arbitrary code execution.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2025-32756 results in unauthenticated remote code execution, granting attackers the ability to compromise the confidentiality, integrity, and availability of the affected Fortinet appliances. These devices are often positioned at the network perimeter, and their compromise could facilitate deeper network penetration or interception of organizational traffic.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade FortiMail to 7.0.9, 7.2.8, 7.4.5, 7.6.3 or later.</li>
<li>Upgrade FortiNDR to 7.0.7, 7.2.5, 7.4.8, 7.6.1 or later.</li>
<li>Upgrade FortiRecorder to 6.4.6, 7.0.6, 7.2.4 or later.</li>
<li>Upgrade FortiVoice to 6.4.11, 7.0.7, 7.2.1 or later.</li>
<li>Upgrade FortiCamera to 2.1.4 or later.</li>
<li>Monitor web server access logs for anomalous POST or GET requests targeting the '/remote/hostcheck_validate' path, specifically looking for unusually long or malformed 'AuthHash' cookie strings.</li>
<li>Implement access controls to restrict exposure of administrative or authentication-related endpoints to untrusted networks.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>buffer-overflow</category><category>vulnerability</category></item></channel></rss>