---
cve: "CVE-2025-48839"
severity: "MEDIUM"
cvss: 6.3
epss: "36%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2025-11-18 17:16:02"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T10:48:32+02:00"
---

# CVE-2025-48839

> 6.3 MEDIUM

## Beschreibung

An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-787** — Out-of-bounds Write
  The product writes data past the end, or before the beginning, of the intended buffer.

## Referenzen

- <https://fortiguard.fortinet.com/psirt/FG-IR-25-225>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-48839) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
