Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-54822


An improper authorization vulnerability [CWE-285] in Fortinet FortiOS version 7.4.0 through 7.4.1 and before 7.2.8 & Fortinet FortiProxy before version 7.4.8 allows an authenticated attacker to access static files of others VDOMs via crafted HTTP or HTTPS requests.


Published

2025-10-14T16:15:39.180

Last Modified

2025-10-15T17:20:21.080

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-285

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System fortinet fortios < 7.2.9 Yes
Operating System fortinet fortios < 7.4.2 Yes
Application fortinet fortiproxy < 7.4.9 Yes

References