Information Exposure Vulnerability in Fortinet FortiFone Products
CVE-2025-47855
9.3CRITICAL
What is CVE-2025-47855?
A vulnerability exists in Fortinet's FortiFone product line that can lead to unauthorized access to sensitive device configuration information. Specifically, versions 7.0.0 to 7.0.1 and 3.0.13 to 3.0.23 are susceptible to exploitation by unauthenticated attackers who can send crafted HTTP or HTTPS requests to retrieve this sensitive data, potentially compromising the security posture of affected organizations.
Affected Version(s)
FortiFone 7.0.0 <= 7.0.1
FortiFone 3.0.13 <= 3.0.23