CVE-2025-25250

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiSASE 25.1.c may allow an authenticated user to access full SSL-VPN settings via crafted URL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortisase:25.1.75:*:*:*:-:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-06-10 17:21

Updated : 2026-06-23 13:16


NVD link : CVE-2025-25250

Mitre link : CVE-2025-25250

CVE.ORG link : CVE-2025-25250


JSON object : View

Products Affected

fortinet

  • fortios
  • fortisase
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor