CVE-2025-54838
An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.
Exploited
Not listed
EPSS
0.003
21.2th percentile
Discovered by
Vendor
Vendor advisory field
Published
Dec 9, 2025
Assigned by fortinet
Description
An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.
Weakness: CWE-863
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiPortal | Network & Security Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiPortal
Credit
Internally discovered and reported by Hisham AboulMakarem of Fortinet Systems Engineer team.
Vendor remediation
Upgrade to FortiPortal version 7.4.6 or above