Out-of-bounds write in multiple endpoints

Summary

An Out-of-bounds Write vulnerability [CWE-787] in FortiADC may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.

Version Affected Solution
FortiADC 8.0 8.0.0 Upgrade to 8.0.1 or above
FortiADC 7.6 7.6.0 through 7.6.2 Upgrade to 7.6.3 or above
FortiADC 7.4 7.4.0 through 7.4.7 Upgrade to 7.4.8 or above
FortiADC 7.2 7.2 all versions Migrate to a fixed release
FortiADC 7.1 7.1 all versions Migrate to a fixed release
FortiADC 7.0 7.0 all versions Migrate to a fixed release
FortiADC 6.2 6.2 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Kentaro Kawane from GMO Cybersecurity by Ierae for reporting this vulnerability under responsible disclosure.

Timeline

2025-11-18: Initial publication