{"id":"CVE-2025-54821","title":"An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, F…","summary":"An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, F…","severity":"low","cvss":1.9,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-269"],"vendor":"fortinet","product":"fortiproxy","affected":["fortiproxy >= 7.0.0, < 7.6.4","fortipam >= 1.0.0, < 1.6.1","fortios >= 6.4.0, < 7.6.4"],"patched":["fortiproxy 7.6.4","fortipam 1.6.1","fortios 7.6.4"],"published":"2025-11-18","updated":"2026-06-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-54821","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-25-545","label":"psirt@fortinet.com"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-864900.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}],"tags":["nvd"],"epss":0.00152,"epssPercentile":0.04769,"ingestedAt":"2026-06-29T13:24:34.603Z","slug":"CVE-2025-54821","body":"## Overview\n\nAn Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSASE 25.2.91 may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command.\n\n## Affected\n\n- `fortiproxy >= 7.0.0, < 7.6.4`\n- `fortipam >= 1.0.0, < 1.6.1`\n- `fortios >= 6.4.0, < 7.6.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fortiproxy 7.6.4`\n- `fortipam 1.6.1`\n- `fortios 7.6.4`","depth":"sunlit","depthScore":10,"depthScoreParts":{"impact":10.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}