CVE-2025-25250
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all ve
Severity
Low 3.9
CVSS 3.1
Exploited
Not listed
EPSS
0.005
37.4th percentile
Discovered by
Not disclosed
Published
Jun 10, 2025
Assigned by fortinet
Description
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiSASE 25.1.c may allow an authenticated user to access full SSL-VPN settings via crafted URL.
Weakness: CWE-200
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
| Fortinet | FortiSASE | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (3)
- Fortinet · FortiOS
- Fortinet · FortiSASE
- Siemens · RUGGEDCOM APE1808
Vendor remediation
Upgrade to FortiOS version 7.6.1 or above Upgrade to FortiOS version 7.4.8 or above Fortinet remediated this issue in FortiSASE version 25.2.a and hence customers do not need to perform any action.