CVE-2025-59921

MEDIUM

FortiADC 6.2.0-7.4.0 - Authenticated Exposure of Sensitive Information via HTTP Requests

Title source: llm
STIX 2.1

Description

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version 7.1.4 and below, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to obtain sensitive data via crafted HTTP or HTTPs requests.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0020
EPSS Percentile 42.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
fortinet/fortiadc 7.4.0
fortinet/fortiadc 6.2.0 - 7.1.5
Published Oct 14, 2025
Tracked Since Feb 18, 2026