An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-545 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-11-18 17:16
Updated : 2026-01-14 10:16
NVD link : CVE-2025-54821
Mitre link : CVE-2025-54821
CVE.ORG link : CVE-2025-54821
JSON object : View
Products Affected
fortinet
- fortiproxy
- fortios
- fortipam
CWE
CWE-269
Improper Privilege Management
