CVE-2025-54822
14.10.2025, 16:15
An improper authorization vulnerability [CWE-285] in Fortinet FortiOS version 7.4.0 through 7.4.1 and before 7.2.8 & Fortinet FortiProxy before version 7.4.8 allows an authenticated attacker to access static files of others VDOMs via crafted HTTP or HTTPS requests.Enginsight
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortios | 7.0.0 ≤ 𝑥 < 7.2.9 |
| fortinet | fortios | 7.4.0 ≤ 𝑥 < 7.4.2 |
| fortinet | fortiproxy | 2.0.0 ≤ 𝑥 < 7.4.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration