Fortinet FortiManager fgtupdates Vulnerability Allows Attackers to Execute Malicious Commands
ID: d97d03fb-af7c-5f65-91c9-1d9d85d0deaf
STIX ID: report--d97d03fb-af7c-5f65-91c9-1d9d85d0deaf
Feed Name: cybersecurityNews.com
Fortinet disclosed a high-severity stack-based buffer overflow (CVE-2025-54820, CVSSv3 7.0) in the FortiManager fgtupdates service that could permit remote unauthenticated command execution if the service is enabled and stack protections are bypassed. Affected on‑prem versions include FortiManager 7.4 (through 7.4.2), 7.2 (through 7.2.10), and all 6.4 releases; FortiManager Cloud is not affected. Fortinet recommends upgrading to patched releases or disabling the fgtupdates service as a temporary workaround and advises administrators to audit deployments and monitor for anomalous access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
