← Back

CVE-2025-61624

nvd nist
Published: Apr 14, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Exploitability: 1.2 / Impact: 5.2
Source: NVD

Description

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSwitchManager 7.2.0 through 7.2.7, FortiSwitchManager 7.0.0 through 7.0.6 may allow an authenticated attacker with admin profile and at least read-write permissions to write or delete arbitrary files via specific CLI commands.

Affected (7)

4 products
Fortios
Fortipam
Fortiproxy
Fortiswitchmanager
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.4.0 to 7.4.10
From 7.6.0 to 7.6.5
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0.0 to 1.7.1
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.0.0 to 7.4.12
From 7.6.0 to 7.6.5
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.0.0 to 7.0.7
From 7.2.0 to 7.2.8

References (2)

Source: psirt@fortinet.com
Vendor Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e

Timeline

No history available yet.