Unchecked Return Value Vulnerability in Fortinet FortiOS
CVE-2025-58903

2.5LOW

Key Information:

Vendor

Fortinet

Status
Vendor
CVE Published:
14 October 2025

What is CVE-2025-58903?

A vulnerability in Fortinet’s FortiOS allows authenticated users to exploit unhandled return values within the API, specifically in versions 7.6.0 to 7.6.3 and earlier than 7.4.8. This can lead to a Null Pointer Dereference, resulting in the crashing of the http daemon when a specially crafted request is made. Proper validation and handling of return values are essential to mitigate this risk and ensure the security and stability of the affected systems.

Affected Version(s)

FortiOS 7.6.0 <= 7.6.3

FortiOS 7.4.0 <= 7.4.8

FortiOS 7.2.0 <= 7.2.12

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-58903 : Unchecked Return Value Vulnerability in Fortinet FortiOS