Authentication Bypass Vulnerability in Fortinet FortiProxy and FortiOS
CVE-2025-22252

7.2HIGH

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
28 May 2025

What is CVE-2025-22252?

The vulnerability allows an attacker to exploit a missing authentication for a critical function in specified versions of Fortinet FortiProxy, FortiSwitchManager, and FortiOS. By leveraging an existing admin account, the attacker can bypass authentication measures, potentially gaining unauthorized administrative access to the affected devices. This poses a significant risk to the overall security and integrity of network systems relying on these Fortinet products.

Affected Version(s)

FortiOS 7.6.0

FortiOS 7.4.4 <= 7.4.6

FortiProxy 7.6.0 <= 7.6.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-22252 : Authentication Bypass Vulnerability in Fortinet FortiProxy and FortiOS