CVE-2025-22254

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16,

Severity
Medium 6.5
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.008
56.7th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jun 10, 2025
Assigned by fortinet

Description

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiWeb 7.6.0 through 7.6.1, FortiWeb 7.4.0 through 7.4.6 allows an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module.

Weakness: CWE-269

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Check your version Firewall / NGFW cna-assigner
Fortinet FortiProxy Check your version SASE / SSE / Secure Web cna-assigner
Fortinet FortiWeb Check your version Web & Application Security cna-assigner
Vendor-reported products (3)
  • Fortinet · FortiOS
  • Fortinet · FortiProxy
  • Fortinet · FortiWeb

Credit

Internally discovered and reported by Justin Lum of Fortinet developpement team.

Vendor remediation

Upgrade to upcoming FortiAuthenticator version 7.0.0 or above Upgrade to FortiOS version 7.6.2 or above Upgrade to FortiOS version 7.4.7 or above Upgrade to FortiOS version 7.2.11 or above Upgrade to FortiOS version 7.0.17 or above Upgrade to FortiOS version 6.4.16 or above Upgrade to FortiProxy version 7.6.2 or above Upgrade to FortiProxy version 7.4.8 or above Upgrade to FortiProxy version 7.2.13 or above Upgrade to FortiProxy version 7.0.20 or above Upgrade to FortiWeb version 7.6.2 or above Upgrade to FortiWeb version 7.4.7 or above

Something wrong here?