CVE-2025-25250

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiSASE 25.1.c may allow an authenticated user to access full SSL-VPN settings via crafted URL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortisase:25.1.75:*:*:*:-:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:*

History

23 Jun 2026, 13:16

Type Values Removed Values Added
Summary (en) An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL. (en) An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiSASE 25.1.c may allow an authenticated user to access full SSL-VPN settings via crafted URL.

09 Jun 2026, 10:16

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-864900.html -

22 Jul 2025, 17:52

Type Values Removed Values Added
First Time Fortinet fortios
Fortinet
Fortinet fortisase
CPE cpe:2.3:a:fortinet:fortisase:25.1.75:*:*:*:-:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:*
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-257 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-257 - Vendor Advisory

12 Jun 2025, 16:06

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de exposición de información confidencial a un actor no autorizado [CWE-200] en FortiOS versión 7.6.0, versión 7.4.7 y anteriores, 7.2 todas las versiones, 7.0 todas las versiones, 6.4 todas las versiones. El modo web de SSL-VPN puede permitir que un usuario autenticado acceda a la configuración completa de SSL-VPN a través de una URL manipulada.

10 Jun 2025, 17:21

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-10 17:21

Updated : 2026-06-23 13:16


NVD link : CVE-2025-25250

Mitre link : CVE-2025-25250

CVE.ORG link : CVE-2025-25250


JSON object : View

Products Affected

fortinet

  • fortios
  • fortisase
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor