CVE-2025-22252

CRITICAL

Fortinet Fortiproxy < 7.4.7 - Missing Authentication

Title source: rule

Description

A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication bypass.

Exploits (1)

github WRITEUP 7 stars
by cybersecplayground · poc
https://github.com/cybersecplayground/PoC-and-CVE-Reports/tree/main/2025/CVE-2025-22252.md

Scores

CVSS v3 9.8
EPSS 0.0024
EPSS Percentile 47.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (4)
fortinet/fortios 7.6.0
fortinet/fortios 7.4.4 - 7.4.7
fortinet/fortiproxy 7.6.0
fortinet/fortiswitchmanager 7.2.5
Published May 28, 2025
Tracked Since Feb 18, 2026