CVE-2025-22252
CRITICALFortinet Fortiproxy < 7.4.7 - Missing Authentication
Title source: ruleDescription
A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication bypass.
Exploits (1)
github
WRITEUP
7 stars
by cybersecplayground · poc
https://github.com/cybersecplayground/PoC-and-CVE-Reports/tree/main/2025/CVE-2025-22252.md
Scores
CVSS v3
9.8
EPSS
0.0024
EPSS Percentile
47.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-306
Status
published
Products (4)
fortinet/fortios
7.6.0
fortinet/fortios
7.4.4 - 7.4.7
fortinet/fortiproxy
7.6.0
fortinet/fortiswitchmanager
7.2.5
Published
May 28, 2025
Tracked Since
Feb 18, 2026