---
id: CVE-2025-60024
title: >-
  Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path
  Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice
  7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged
  authenticat…
summary: >-
  Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path
  Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice
  7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged
  authenticat…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: fortinet
product: fortivoice
affected:
  - 'fortivoice >= 7.0.0, < 7.0.8'
  - 'fortivoice >= 7.2.0, < 7.2.3'
patched:
  - fortivoice 7.2.3
published: '2025-12-09'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-60024'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-25-812'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.00455
epssPercentile: 0.36888
ingestedAt: '2026-09-25T23:21:16.903Z'
---

## Overview

Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged authenticated attacker to write arbitrary files via specifically HTTP or HTTPS commands

## Affected

- `fortivoice >= 7.0.0, < 7.0.8`
- `fortivoice >= 7.2.0, < 7.2.3`

## Remediation

Upgrade past the affected range:

- `fortivoice 7.2.3`
