CVE-2025-54821

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSASE 25.2.91 may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fortinet:fortipam:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-18 17:16

Updated : 2026-06-23 13:16


NVD link : CVE-2025-54821

Mitre link : CVE-2025-54821

CVE.ORG link : CVE-2025-54821


JSON object : View

Products Affected

fortinet

  • fortios
  • fortipam
  • fortiproxy
CWE
CWE-269

Improper Privilege Management