Improper Authorization in FortiProxy and FortiOS - CVE-2025-54822

 

Improper Authorization in FortiProxy and FortiOS - CVE-2025-54822

Published: October 14, 2025


Vulnerability identifier: #VU117139
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54822
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

The vulnerability exists due to improper authorization. An authenticated attacker can access static files of others VDOMs via crafted HTTP or HTTPS requests.


Affected software

FortiProxy
FortiOS

How to mitigate CVE-2025-54822

Install update from vendor's website.

FortiProxy - update to 7.4.9
FortiOS - addressed in versions 7.2.9, 7.4.2

External References

Related Security Bulletins