A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted http requests
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-010 | Vendor Advisory |
Configurations
History
14 Jan 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted http requests |
15 Oct 2025, 17:18
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Fortinet fortipam
Fortinet Fortinet fortiswitchmanager |
|
| CPE | cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortipam:1.5.0:*:*:*:*:*:*:* |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-25-010 - Vendor Advisory |
14 Oct 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-14 16:15
Updated : 2026-01-14 10:16
NVD link : CVE-2025-49201
Mitre link : CVE-2025-49201
CVE.ORG link : CVE-2025-49201
JSON object : View
Products Affected
fortinet
- fortiswitchmanager
- fortipam
CWE
CWE-1390
Weak Authentication
