Fortinet Confirms Active Exploitation of Critical 0-Day in FortiVoice and Related Systems
A severe vulnerability (CVE-2025-32756) is being actively exploited in the wild, targeting Fortinet’s FortiVoice systems. This critical flaw—rated 9.6 on the CVSS scale—can allow remote attackers to take full control of vulnerable systems without authentication, simply by sending a specially crafted HTTP request.
The issue, which stems from a stack-based buffer overflow, also affects other Fortinet products including FortiMail, FortiNDR, FortiRecorder, and FortiCamera. Fortinet confirmed that exploitation attempts were first detected against FortiVoice systems, prompting immediate investigation and patch releases.
What’s at Stake
Unlike many vulnerabilities that require user interaction or elevated privileges, CVE-2025-32756 can be triggered remotely and anonymously. This makes it especially dangerous, as attackers can seize control over devices without needing credentials or internal access.
According to Fortinet’s advisory published on May 13, 2025, successful exploitation could lead to arbitrary command or code execution, potentially enabling cybercriminals to install malware, extract data, or pivot deeper into enterprise networks.
Inside the Attack Campaign
Security teams monitoring the situation have uncovered concrete signs of exploitation. In several confirmed breaches, attackers conducted:
- Network probing to map out connected systems
- Log tampering, including deletion of crash logs, to cover their tracks
- Activation of FCGI debugging, a tool abuse method used to steal credentials or monitor logins
Investigators also reported the presence of unauthorized cron jobs and modified system files aimed at data exfiltration.
Known Malicious IPs Linked to Attacks:
- 198.105.127.124
- 218.187.69.244
- (4 additional IPs have been identified but not publicly disclosed)
Security teams are urged to scan for indicators of compromise (IoCs), including unexpected log entries in the httpd trace files, alterations to key configurations, and unusual process behaviors.
Observed Indicators and Attack Artifacts
| Category | Indicator / File / IP | Details & Purpose |
|---|---|---|
| HTTPD Log Anomalies | mod_fcgid: error reading data, FastCGI server closed connection | Warning in Apache logs showing unusual FastCGI behavior |
mod_fcgid: process /migadmin/www/fcgi/admin.fe(...) exit(communication error) | HTTPD trace log records a segmentation fault (signal 11), indicating process crash | |
| Malware & Dropped Files | /bin/wpad_ac_helper (MD5: 4410352e110f82eabc0bf160bec41d21) | Primary malware binary deployed by attackers |
/bin/busybox (MD5s: ebce43017d2cb316ea45e08374de7315, 489821c38f429a21e1ea821f8460e590) | Maliciously replaced system utility | |
/lib/libfmlogin.so (MD5: 364929c45703a84347064e2d5de45bcd) | Injected shared library used to intercept SSH credentials | |
/tmp/.sshdpm | Temporary file storing harvested credentials | |
/bin/fmtest (MD5: 2c8834a52faee8d87cff7cd09c4fb946) | Custom network scanning script | |
/var/spool/.sync | Target location for exfiltrated credentials | |
| Modified System Files | /data/etc/crontab | Cron task added to grep credentials from FastCGI debug logs |
/var/spool/cron/crontabs/root | Cron task scheduled to back up FastCGI logs | |
/etc/pam.d/sshd | Configuration altered to preload malicious login capture library | |
/etc/httpd.conf | Injected line to enable a SOCKS5 module | |
| Backdoor Configuration | FCGI Debug set to 0x80041, output directed to file | Enables high-level FastCGI logging, capturing credentials |
| Known Attacker IPs | 198.105.127.12443.228.217.17343.228.217.82156.236.76.90218.187.69.244218.187.69.59 | IP addresses tied to malicious activity |
| Suspicious Cron Jobs | 0 */12 * * * root busybox grep -rn passw /var/spool/crashlog/fcgi.debug > /var/spool/.sync; cat /dev/null > /var/spool/crashlog/fcgi.debug | Recurring credential dump from logs, executes every 12 hours |
0 */12 * * * root cat /var/spool/crashlog/fcgi.debug > /var/spool/.sync; cat /dev/null > /var/spool/crashlog/fcgi.debug | Log rotation and credential capture process, also every 12 hours |
Wide-Ranging Fortinet Exploit Targets Key Network Infrastructure – Urgent Patching Required
A critical security flaw has been identified across multiple Fortinet product lines, with attackers actively exploiting FortiVoice systems. This vulnerability impacts a broad swath of product versions, making swift action essential to prevent potential compromise.
Products & Versions at Risk:
- FortiVoice: Versions 6.4.0–6.4.10, 7.0.0–7.0.6, and 7.2.0
- FortiMail: All builds up to 7.6.2
- FortiNDR: All 1.x releases and 7.x builds prior to 7.6.1
- FortiRecorder: Versions through 7.2.3
- FortiCamera: Up to version 2.1.3
Fortinet has issued updated firmware for all affected platforms. Organizations are strongly advised to upgrade immediately. For those unable to deploy patches right away, disabling the web-based (HTTP/HTTPS) administrative access can reduce exposure temporarily.
A Broader Pattern of Risk
This is not an isolated event. The vulnerability (CVE-2025-32756) adds to a growing list of high-impact flaws in Fortinet’s portfolio:
- Early 2025: CVE-2024-55591, a critical flaw under active attack, was patched.
- Late 2022: CVE-2022-40684, an authentication bypass, was exploited by nation-state actors including groups tied to China and Russia.
Why It Matters
Devices like FortiVoice aren’t just infrastructure—they’re communication lifelines embedded deep in enterprise networks. Their access to internal systems, voice traffic, and administrative privileges makes them a prime target for attackers seeking lateral movement or data theft.
Act Now
Organizations using any of the listed products should treat this as a high-priority threat. Applying the latest patches or temporarily disabling vulnerable services could mean the difference between a blocked attack and a full network breach.




