CVE-2025-25250EPSS p37.5%

CVE-2025-25250CVE-2025-25250

fortinet / fortisase

Description

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiSASE 25.1.c may allow an authenticated user to access full SSL-VPN settings via crafted URL.

Scoring

CVSS 4.3 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS0.46% probability of exploitation · percentile 37.5% · 2026-08-03T12:00:16Z
Last modified2026-06-23

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-47855
CVE
CVE-2025-22256
CVE
CVE-2025-52970
CVE
CVE-2025-25248
CVE
CVE-2025-47890
CVE
CVE-2025-24470
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.