CVE-2025-58693
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker
Exploited
Not listed
EPSS
0.007
50.3th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jan 13, 2026
Assigned by fortinet
Description
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
Weakness: CWE-22
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiVoice | Other Products | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiVoice
Credit
Internally reported and discovered by Jaguar Perlas of Burnaby Infosec team.
Vendor remediation
Upgrade to FortiVoice version 7.2.3 or above Upgrade to FortiVoice version 7.0.8 or above