01/15/2026
FORTINET -
EZ Access Communications has been notified of a security advisory addressing a vulnerability in Fortinet products. Fortinet has patched the vulnerability that could allow unauthenticated users to execute arbitrary code or commands via specifically crafted requests.
Vendor: Fortinet (FortiOS and FortiSwitchManager)
CVE(s): CVE-2025-25249
CVSS: 7.4 (High)
In the Wild: No
Unauthenticated: Yes
Description: A heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
Impact: This vulnerability could enable attackers to gain admin-level privileges on affected systems.
Workarounds: Yes, temporary workarounds are available until upgrading to a non-affected version.
Link to source(s): Fortinet Security Advisory
Indicators of Compromise (IOC) available: No
Recommendations: Review the vendor advisory, confirm applicability, apply the workaround, and update to a patched version as soon as feasible.
If you need assistance reviewing or implementing the temporary workaround, patching impacted Fortinet products, or discussing these vulnerabilities in more detail, please contact me and we will set up a call.