---
id: CVE-2025-25250
title: >-
  An Exposure of Sensitive Information to an Unauthorized Actor vulnerability
  [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through
  7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all
  versions, For…
summary: >-
  An Exposure of Sensitive Information to an Unauthorized Actor vulnerability
  [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through
  7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all
  versions, For…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: fortinet
product: fortisase
affected:
  - fortisase = 25.1.75
  - 'fortios >= 6.4.0, < 7.4.8'
  - fortios = 7.6.0
patched:
  - fortios 7.4.8
published: '2025-06-10'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-25250'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-24-257'
    label: psirt@fortinet.com
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-864900.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.00536
epssPercentile: 0.4277
ingestedAt: '2026-06-29T13:24:34.364Z'
---

## Overview

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiSASE 25.1.c may allow an authenticated user to access full SSL-VPN settings via crafted URL.

## Affected

- `fortisase = 25.1.75`
- `fortios >= 6.4.0, < 7.4.8`
- `fortios = 7.6.0`

## Remediation

Upgrade past the affected range:

- `fortios 7.4.8`
