← Back

CVE-2025-54821

nvd nist
Published: Nov 18, 2025Modified: Jun 23, 2026

JSON object

Loading...
6.0
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Exploitability: 0.8 / Impact: 5.2
Source: NVD

Description

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSASE 25.2.91 may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command.

Affected (3)

3 products
Fortiproxy
Fortipam
Fortios
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 7.0.0 to 7.6.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0.0 to 1.6.1
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
From 6.4.0 to 7.6.4

References (2)

Source: psirt@fortinet.com
Vendor Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e

Timeline

No history available yet.