A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-259 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
20 Nov 2025, 14:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-25-259 - Vendor Advisory | |
| First Time |
Fortinet fortiextender Firmware
Fortinet fortiextender Fortinet |
|
| CPE | cpe:2.3:o:fortinet:fortiextender_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:fortinet:fortiextender:-:*:*:*:*:*:*:* |
18 Nov 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-18 17:16
Updated : 2025-11-20 14:40
NVD link : CVE-2025-46775
Mitre link : CVE-2025-46775
CVE.ORG link : CVE-2025-46775
JSON object : View
Products Affected
fortinet
- fortiextender
- fortiextender_firmware
CWE
CWE-1295
Debug Messages Revealing Unnecessary Information
