CVE-2025-22252

A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication bypass.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiproxy:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiswitchmanager:7.2.5:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:7.6.0:*:*:*:*:*:*:*

History

04 Jun 2025, 14:35

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-28 08:15

Updated : 2025-06-04 14:35


NVD link : CVE-2025-22252

Mitre link : CVE-2025-22252

CVE.ORG link : CVE-2025-22252


JSON object : View

Products Affected

fortinet

  • fortios
  • fortiswitchmanager
  • fortiproxy
CWE
CWE-306

Missing Authentication for Critical Function