CNNVD-202602-1623 Information

CNNVD ID

CNNVD-202602-1623

CVE-2025-64157

  • CNNVD Published: 2026-02-10

Description (Chinese)

Fortinet FortiOS是美国飞塔(Fortinet)公司的一套专用于FortiGate网络安全平台上的安全操作系统。该系统为用户提供防火墙、防病毒、IPSec/SSLVPN、Web内容过滤和反垃圾邮件等多种安全功能。 Fortinet FortiOS 7.6.0版本至7.6.4版本、7.4.0版本至7.4.9版本、7.2.0版本至7.2.11版本和7.0所有版本存在格式化字符串错误漏洞,该漏洞源于使用外部控制的格式字符串,可能导致执行未经授权的代码或命令。

Description (English)

Fortinet FortiOS is a security operating system dedicated to the FortiGate network security platform of the United States of America. The system provides a wide range of security features for users, including firewalls, anti-virus, IPSEc/SSLVPN, Web content filters and anti-spam. Fortinet FortiOS 7.6.0 to 7.6.4, version 7.4.0 to version 7.4.9, version 7.2.0 to version 7.2.11 and all version 7.0 have a formatted string error loop, which results from a format string using external control and may result in the performance of an unauthorized code or command.

Vulnerability Type

格式化字符串错误

Affected Vendor

飞塔

Published

2026-02-10

Last Modified

2026-02-24

References

https://fortiguard.fortinet.com/psirt/FG-IR-25-795 https://access.redhat.com/security/cve/cve-2025-64157

Patch

https://fortiguard.fortinet.com/psirt/FG-IR-25-795

Share on: