SB2025111873 - Improper privilege management in Fortinet products
Published: November 18, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper privilege management (CVE-ID: CVE-2025-54821)
The vulnerability allows a local privileged user to manipulate data.
The vulnerability exists due to improper privilege management via SSH. An authenticated administrator can bypass the trusted host policy via crafted CLI command.
Remediation
Install update from vendor's website.