Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-22252


A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication bypass.


Published

2025-05-28T08:15:21.070

Last Modified

2025-06-04T14:35:38.543

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiproxy 7.6.0 Yes
Application fortinet fortiswitchmanager 7.2.5 Yes
Operating System fortinet fortios < 7.4.7 Yes
Operating System fortinet fortios 7.6.0 Yes

References