983,992 Indexed FortiGate Instances: Reading an Edge-Appliance Count Against CVE-2025-25249
Edge appliances are difficult to measure honestly, because exposure and importance are unrelated properties. A firewall with a pre-authentication packet-processing flaw and a firewall that has never been reachable from an untrusted network can appear in the same fingerprint count. CVE-2025-25249, added to CISA's Known Exploited Vulnerabilities catalog on 9 September 2026, is a case where the measurement and the advisory need to be read together.
What was measured and how
The measurement used a single fingerprint query on 23 September 2026: app="FortiGate". It returned 983,992 matching assets. The unit is an indexed asset matching the ZoomEye fingerprint at the recorded collection time. ZoomEye updates its index continuously, so the number describes the population as observed at collection rather than a fixed total.
The fingerprint approach was chosen because FortiGate devices present distinguishing characteristics on their web interfaces. That makes the query more selective than a port-based count would be, and it is why the figure is reported here as a product population rather than as a service count.
What the advisory establishes
CISA's entry states that FortiOS, FortiSwitchManager and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. It is classified under CWE-122 and CWE-787. The vendor advisory is FG-IR-25-084, and the identifier carries a 2025 prefix, which places the assignment roughly a year before the exploited-vulnerabilities listing.
The phrase specially crafted packets locates the flaw in the packet-processing path. That is the code that runs before authentication, which means the prerequisite is reachability and nothing else.
What 983,992 supports
The count supports a capacity argument. Almost a million visible instances is a target set large enough that automated scanning can be expected to find vulnerable hosts without deliberate effort, and a pre-authentication memory-corruption flaw needs only a reachable instance and a crafted packet sequence. In that situation the population figure is a reasonable proxy for how quickly opportunistic exploitation can find candidates.
It also supports an inventory argument. The population size means most mid-sized and large organisations are likely to operate at least one such device, and a patch programme for this class of equipment needs an accurate device inventory before it can be scheduled. A number this large shows that the inventory problem comes before the patch itself.
What 983,992 cannot support
Four limits matter here, and they are unusually important because the flaw is a memory-safety bug.
The count does not reveal firmware versions. FortiOS releases are numerous, and a fingerprint match is not a version disclosure. The total cannot tell you how many of these devices run an affected release.
The count does not separate devices placed at the network edge from those deployed internally or in a lab. The flaw's consequence depends heavily on position: an appliance that terminates untrusted traffic is exposed to crafted packets from the internet, while an appliance used only for internal segmentation is exposed to crafted packets from inside the network. Those are meaningfully different risk statements, and the fingerprint does not distinguish them.
The count does not indicate support status. Appliances that have passed end of support remain visible and remain in service, and they will not receive the fix through the vendor's normal update path.
The count does not measure exploitation. CISA added the entry because evidence of exploitation exists somewhere. Nothing in a fingerprint total identifies where, and treating the population figure as an incident count would be a mistake.
A repeatable method
The most useful property of a product fingerprint is that it can be re-run. Two applications follow.
Externally, the query can be scheduled and compared over time, which shows whether a device class is growing or contracting in exposure. For a platform that carries perimeter traffic, a rising count is worth understanding.
Internally, the same fingerprint logic can be applied to an organisation's own address ranges. ZoomEye accepts network scoping parameters, so the question shifts from how many FortiGate devices exist on the internet to which of ours are reachable from outside the perimeter. That is an inventory answer, it is specific to one estate, and it is what a patch programme needs.
References
- ZoomEye fingerprint query app="FortiGate", collected 23 September 2026: 983,992 matching assets
- CISA, Known Exploited Vulnerabilities Catalog, entry for CVE-2025-25249 (added 9 September 2026, due 12 September 2026): https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Fortinet PSIRT advisory FG-IR-25-084: https://fortiguard.fortinet.com/psirt/FG-IR-25-084
Top comments (0)