Junglewise Threat Intelligence

CVE-2025-25250: Fortinet FortiOS information disclosure in SSL-VPN web-mode

CVE-2025-25250 · Severity: medium · CVSS 4.3 · Published 2025-06-10

Technologies: Siemens Ruggedcom Ape1808, Fortinet FortiOS, Fortinet Fortisase. Vendors: Siemens, Fortinet.

Executive brief

A vulnerability in Fortinet's networking software could allow a logged-in user to view sensitive configuration settings for the SSL-VPN service. This service is typically used to provide secure remote access to corporate networks for employees. If exploited, an attacker could gain detailed information about how the VPN is configured, which could potentially be used to plan further attacks or identify other weaknesses in the network's security posture.

Technical details

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability (CWE-200) exists in the SSL-VPN web-mode component of FortiOS. The flaw is rooted in insufficient access control on specific endpoints, allowing a remote attacker with valid user-level credentials to bypass intended restrictions. By sending a specially crafted URL to the SSL-VPN portal, an authenticated user can retrieve the full SSL-VPN configuration settings. This disclosure could reveal internal network details or security parameters. Fortinet recommends upgrading to FortiOS 7.6.1, 7.4.8, or migrating to a fixed release for older branches.

Affected products

  • Fortinet FortiOS 7.6.0, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions
  • Fortinet FortiSASE 25.1.c
  • Siemens RUGGEDCOM APE1808 (Fortinet NGFW) Versions with FortiOS < 7.4.9

Timeline

  • 2025-05-13: advisory: Siemens published initial advisory SSA-864900
  • 2025-06-10: disclosed: Initial publication by Fortinet (FG-IR-24-257) and NVD

References

Related threats