Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-57823


A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints


Published

2025-12-09T18:15:54.480

Last Modified

2025-12-09T19:45:32.077

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 2.7 (LOW)

Weaknesses
  • Type: Primary
    CWE-425

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiauthenticator ≤ 6.6.6 Yes

References