CVE-2025-22251

LOW

FortiOS 6.4.0-7.4.5, 7.6.0 - Unauthenticated Session Injection via FGSP Packet

Title source: llm
STIX 2.1

Description

An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.

References (1)

Core 1
Core References

Scores

CVSS v3 3.1
EPSS 0.0021
EPSS Percentile 43.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-923
Status published
Products (2)
fortinet/fortios 7.6.0
fortinet/fortios 6.4.0 - 7.4.6
Published Jun 10, 2025
Tracked Since Feb 18, 2026