CVE-2025-46775

A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:fortinet:fortiextender_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortiextender_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fortinet:fortiextender:-:*:*:*:*:*:*:*

History

20 Nov 2025, 14:40

Type Values Removed Values Added
References () https://fortiguard.fortinet.com/psirt/FG-IR-25-259 - () https://fortiguard.fortinet.com/psirt/FG-IR-25-259 - Vendor Advisory
First Time Fortinet fortiextender Firmware
Fortinet fortiextender
Fortinet
CPE cpe:2.3:o:fortinet:fortiextender_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fortinet:fortiextender:-:*:*:*:*:*:*:*

18 Nov 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-18 17:16

Updated : 2025-11-20 14:40


NVD link : CVE-2025-46775

Mitre link : CVE-2025-46775

CVE.ORG link : CVE-2025-46775


JSON object : View

Products Affected

fortinet

  • fortiextender
  • fortiextender_firmware
CWE
CWE-1295

Debug Messages Revealing Unnecessary Information