Cross-Site Scripting Vulnerability in Fortinet FortiADC Products
CVE-2025-58412

4.2MEDIUM

Key Information:

Vendor

Fortinet

Status
Vendor
CVE Published:
19 November 2025

What is CVE-2025-58412?

A vulnerability exists in Fortinet's FortiADC products that allows attackers to exploit improper neutralization of script-related HTML tags within web pages. This flaw permits the execution of unauthorized code or commands upon submitting a specially crafted URL. Versions affected include FortiADC 8.0.0 and multiple minor releases ranging from 7.4 to 7.6.3. It is essential for organizations using these versions to review and implement necessary security patches to mitigate potential risks.

Affected Version(s)

FortiADC 8.0.0

FortiADC 7.6.0 <= 7.6.3

FortiADC 7.4.0 <= 7.4.9

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-58412 : Cross-Site Scripting Vulnerability in Fortinet FortiADC Products