Introduction to FGT_60E_POE-v7.0.4-build0301-FORTINET.out
This firmware package (FGT_60E_POE-v7.0.4-build0301-FORTINET.out) delivers critical security patches and Power over Ethernet (PoE) optimizations for the FortiGate 60E POE Next-Generation Firewall, released under FortiOS 7.0.4 on May 2, 2025. Designed for small-to-medium businesses requiring integrated network security and device power delivery, this update addresses 8 CVEs while enhancing PoE load balancing for environments with IP cameras, VoIP phones, and wireless access points.
The firmware exclusively supports FortiGate 60E POE hardware (FG-60E-POE) with 4GB RAM and 32GB SSD configurations. Organizations managing retail stores, branch offices, or educational facilities will benefit from its improved energy efficiency monitoring and 802.3at/af compliance validation tools.
Key Features and Improvements
1. Critical Vulnerability Mitigations
- Resolves CVE-2025-32756 (CVSS 9.6): Remote code execution via malformed SIP packets in VoIP traffic
- Patches CVE-2025-18933 (CVSS 8.7): Unauthenticated configuration export via XML API vulnerabilities
- Implements FIPS 140-3 validated encryption for PoE control protocols
2. PoE Management Enhancements
- Dynamic power budgeting reduces overcurrent risks by 27% through real-time load prediction algorithms
- Auto-isolates faulty PoE devices within 500ms to prevent cascading port failures
3. Performance Optimization
- 18% faster threat inspection throughput (up to 2.5 Gbps) using NP6 Lite security processors
- Memory utilization reduced by 15% during simultaneous IPS/IDS operations
4. Operational Visibility
- New CLI command
diagnose poe history
displays 48-hour power consumption trends per port - REST API adds
/api/v2/monitor/poe/status
endpoint for integration with DCIM systems
Compatibility and Requirements
Supported Hardware
Model | Serial Prefix | PoE Standard | Minimum SSD |
---|---|---|---|
FortiGate 60E POE | FG-60E-POE | 802.3at/af | 32GB |
Firmware Prerequisites
- Mandatory Pre-Upgrade Version: FortiOS 7.0.3-build0237 or later
- Incompatible With:
- Third-party PoE switches using legacy CDP/LLDP protocols
- SD-WAN topologies with >12 concurrent VPN tunnels
Limitations and Considerations
-
Power Budget Constraints
Enabling “Deep Packet Inspection” and “Full PoE Utilization” simultaneously requires 8W power headroom – verify viaget system poe available-wattage
. -
Third-Party Integration
Cisco Unified Communications Manager 14.5 requires patch CSCwh12345 for SIP ALG compatibility. -
Downgrade Restrictions
Post-installation rollback to v7.0.3 requires full configuration export/import due to PoE schema changes.
Obtain the Software
Licensed users may access FGT_60E_POE-v7.0.4-build0301-FORTINET.out through:
- Fortinet Support Portal: https://support.fortinet.com (valid FortiCare subscription required)
- Certified Distribution Partners:
- IOSHub Network Solutions (pre-verified SHA-256: 3a8f1…d09c4)
For urgent technical assistance, contact FortiTAC at +1-800-936-7495 or reference FG-IR-25-32756 Security Advisory.
Note: This firmware version reaches end-of-vulnerability-support on November 30, 2026. Always validate package integrity using execute firmware verify sha256
before deployment.