CVE-2025-31514General(fortinet / fortios)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fortinet fortios systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via <insert attack vector here>

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios
  • fortiproxy

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-03); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
fortiosfortiproxy

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-03: 1Mentions · 2026-05-15: 1Mentions · 2026-08-19: 1Patch / Workaround · 2026-02-03: 1Technical Details · 2026-02-03: 1Technical Details · 2026-05-15: 1Technical Details · 2026-08-19: 102-0305-1508-19
Signal classification2 categories
General
266.7%
Patch
133.3%
Classification over time
DateTotalLabels
2026-02-031
Patch1
2026-05-151
General1
2026-08-191
General1
Full discourse3 posts
  • 四谷言ノ助@g_yotuya
    General

    @kometchtech 7.4.11のCVEは現在2個 CVE-2025-54821 6.0 CVE-2025-31514 4.3 54821 不適切な特権管理の脆弱性 [CWE-269] により、認証された管理者が細工された CLI コマンドを介して信頼済みホスト ポリシーをバイパスできる可能性があります。

    Post summary

    The post lists two CVEs for Kometchtech 7.4.11, outlines a privilege‑management issue (CVE-2025-54821) that could allow an authenticated administrator to bypass trusted‑host policy via crafted CLI commands, but it provides no PoC, exploit tool, active exploitation claim, or patch information.

    100101.5K
    4.3K followersView on X
  • 四谷言ノ助@g_yotuya
    Patch

    FortiOS 7.4.11が来てるので対応 ちなみに、ひとつ前の7.4.10のスコアは以下の通り FortiOS 7.4.10 CVE-2026-24858 Max CVSS 9.8 EPSS Score 3.71% CVE-2025-54821 Max CVSS 6.0 EPSS Score 0.02% CVE-2025-31514 Max CVSS 4.3 EPSS Score 0.04%

    Post summary

    The post announces the release of FortiOS 7.4.11, highlighting that it addresses several high‑severity CVEs (CVE‑2026‑24858, CVE‑2025‑54821, CVE‑2025‑31514) and providing associated CVSS scores.

    00020414
    4.2K followersView on X
  • 四谷言ノ助@g_yotuya
    General

    FortiOS 7.4.12 今日現在のCVEは6個 CVE-2026-71408 CVE-2026-23573 CVE-2025-62826 CVE-2025-62675 CVE-2025-54821 CVE-2025-31514 CVE-2025-54821 CVSS 6.0 EPSS 0.15 この辺が少し懸念。

    Post summary

    The post lists six CVEs for FortiOS 7.4.12, highlighting CVE‑2025‑54821 with a CVSS score of 6.0 and an EPSS of 0.15 as particularly concerning, but offers no evidence of PoC, exploitation, or mitigation.

    10000237
    4.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
Appfortinetfortiproxy---

Explore more