CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-43892

mediumCVSS 4.3covered by 4 sourcesfirst seen 2026-07-14
CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Revised on 2026-07-14 00:00:00

CSIRTS triage

What
An authenticated remote attacker may return a portion of device memory in the redirect response.
Who is affected
Authenticated users of FortiOS, FortiProxy, and FortiSASE.
Urgency
Remediation is necessary to prevent information disclosure.
Action
Apply the latest patches for FortiOS, FortiProxy, and FortiSASE.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2025-43892

Get an email if CVE-2025-43892 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (4)

External references

NVD record for CVE-2025-43892

CVE.org record

Embed the live status

CVE-2025-43892 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-43892 status](https://www.csirts.com/badge/CVE-2025-43892)](https://www.csirts.com/cve/CVE-2025-43892)