Skip to content

Exploitation reported elsewhere › Fortinet

Reported by CERT-FR

CVE-2025-61624

Fortinet · Security products

Exploitation reported by CERT-FR — not (yet) in CISA’s catalog

In brief

Level of evidence: CISA has not (yet) added it to its catalog of exploited vulnerabilities. The report comes from another official source, cited below.

First reported: April 15, 2026.

Brand and category: the site’s indicative classification, based on the vendor name given by CERT-FR.

Who reports it

Information reused under the Open Licence 2.0 (Etalab); the date of last update is shown for each advisory. This site is neither affiliated with nor endorsed by ANSSI.

What should I do?

Check whether you use this product. If so, apply the fix or workaround given by the vendor, first on devices exposed to the Internet.

Read the CERT-FR publication for affected versions and measures (in French).

If CISA adds it to its catalog, it will join the patch list with its instruction.

Severity and activity

6.5 / 10 CVSS severity: medium

Score from the NVD. Collected Oct 4, 2026.

Vulnerability published: April 14, 2026.

Description

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSwitchManager 7.2.0 through 7.2.7, FortiSwitchManager 7.0.0 through 7.0.6 may allow an authenticated attacker with admin profile and at least read-write permissions to write or delete arbitrary files via specific CLI commands.

Official description from the NVD, collected Oct 4, 2026. CVE® description © The MITRE Corporation.

Sources for this page

  • CERT-FR: advisories and alerts (in French).
  • NVD (NIST): CVSS severity, publication date, description, vendor references.
  • CISA KEV catalog: the vulnerability is not (yet) in it.
  • Brand and category: indicative classification by this site (method).