Improper Privilege Management in Fortinet FortiOS, FortiProxy, and FortiWeb
CVE-2025-22254

6.5MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
10 June 2025

What is CVE-2025-22254?

An Improper Privilege Management vulnerability affecting multiple versions of Fortinet FortiOS, FortiProxy, and FortiWeb allows an authenticated attacker with read-only admin permissions to escalate their privileges to super-admin. This exploitation can occur via specially crafted requests sent to the Node.js websocket module, potentially enabling unauthorized control over the affected systems. To mitigate this risk, it is crucial for users to apply the latest security updates and monitor for any suspicious activity.

Affected Version(s)

FortiOS 7.6.0 <= 7.6.1

FortiOS 7.4.0 <= 7.4.6

FortiOS 7.2.0 <= 7.2.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-22254 : Improper Privilege Management in Fortinet FortiOS, FortiProxy, and FortiWeb