CVE-2025-22254

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiWeb 7.6.0 through 7.6.1, FortiWeb 7.4.0 through 7.4.6 allows an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

14 Jan 2026, 14:16

Type Values Removed Values Added
Summary (en) An Improper Privilege Management vulnerability [CWE-269] affecting Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16 and before 6.4.15, FortiProxy version 7.6.0 through 7.6.1 and before 7.4.7 & FortiWeb version 7.6.0 through 7.6.1 and before 7.4.6 allows an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module. (en) An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiWeb 7.6.0 through 7.6.1, FortiWeb 7.4.0 through 7.4.6 allows an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module.

22 Jul 2025, 21:25

Type Values Removed Values Added
References () https://fortiguard.fortinet.com/psirt/FG-IR-25-006 - () https://fortiguard.fortinet.com/psirt/FG-IR-25-006 - Vendor Advisory
First Time Fortinet fortiweb
Fortinet
Fortinet fortios
Fortinet fortiproxy
CPE cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

12 Jun 2025, 16:06

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de administración inadecuada de privilegios [CWE-269] que afecta a Fortinet FortiOS versión 7.6.0 a 7.6.1, 7.4.0 a 7.4.6, 7.2.0 a 7.2.10, 7.0.0 a 7.0.16 y anteriores a 6.4.15, FortiProxy versión 7.6.0 a 7.6.1 y anteriores a 7.4.7 y FortiWeb versión 7.6.0 a 7.6.1 y anteriores a 7.4.6 permite que un atacante autenticado con al menos permisos de administrador de solo lectura obtenga privilegios de superadministrador a través de solicitudes manipuladas al módulo websocket Node.js.

10 Jun 2025, 17:21

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-10 17:21

Updated : 2026-01-14 14:16


NVD link : CVE-2025-22254

Mitre link : CVE-2025-22254

CVE.ORG link : CVE-2025-22254


JSON object : View

Products Affected

fortinet

  • fortiproxy
  • fortiweb
  • fortios
CWE
CWE-269

Improper Privilege Management