CVE-2025-58903
An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request.
Scoring
- Severity
- LOW
- CVSS base score
- 2.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
- EPSS probability
- 0.62%
- CWE
- CWE-252
- Published
- 2025-10-14
- Last modified
- 2026-08-11
Affected products
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
Weakness type
Related vulnerabilities
- CVE-2021-40401 — A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and d
- CVE-2020-6152 — A code execution vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.7. A spe
- CVE-2026-11972 — tarfile opened in streaming mode mishandles EOF
- CVE-2025-66565 — Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values
- CVE-2026-22861 — iccDEV has a heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp
- CVE-2026-22255 — iccDEV has heap-buffer-overflow in CIccCLUT::Init() at IccProfLib/IccTagLut.cpp
- CVE-2026-22047 — iccDEV has heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp
- CVE-2026-22046 — iccDEV has heap-buffer-overflow in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp