CVE-2025-54821Patch(fortinet / fortios)

LOWCVSS 6.0 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fortinet fortios systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSASE 25.2.91 may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios
  • fortipam
  • fortiproxy

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-03); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
fortiosfortipamfortiproxy

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-03: 1Mentions · 2026-05-15: 1Mentions · 2026-08-19: 1Patch / Workaround · 2026-02-03: 1Technical Details · 2026-02-03: 1Technical Details · 2026-05-15: 1Technical Details · 2026-08-19: 102-0305-1508-19
Signal classification3 categories
Patch
133.3%
Disclosure
133.3%
General
133.3%
Classification over time
DateTotalLabels
2026-02-031
Patch1
2026-05-151
Disclosure1
2026-08-191
General1
Full discourse3 posts
  • 四谷言ノ助@g_yotuya
    Disclosure

    @kometchtech 7.4.11のCVEは現在2個 CVE-2025-54821 6.0 CVE-2025-31514 4.3 54821 不適切な特権管理の脆弱性 [CWE-269] により、認証された管理者が細工された CLI コマンドを介して信頼済みホスト ポリシーをバイパスできる可能性があります。

    Post summary

    The tweet lists two CVEs for KometchTech 7.4.11, describing CVE‑2025‑54821 as a privilege‑management flaw that could let authenticated admins bypass trusted host policy using crafted CLI commands, while also noting CVE‑2025‑31514. No PoC, exploit, patch, or active‑exploitation evidence is provided.

    100101.5K
    4.3K followersView on X
  • 四谷言ノ助@g_yotuya
    Patch

    FortiOS 7.4.11が来てるので対応 ちなみに、ひとつ前の7.4.10のスコアは以下の通り FortiOS 7.4.10 CVE-2026-24858 Max CVSS 9.8 EPSS Score 3.71% CVE-2025-54821 Max CVSS 6.0 EPSS Score 0.02% CVE-2025-31514 Max CVSS 4.3 EPSS Score 0.04%

    Post summary

    A new FortiOS 7.4.11 release is available to address CVE-2026-24858, CVE-2025-54821, and CVE-2025-31514, with prior version 7.4.10 scores listed for reference.

    00020414
    4.2K followersView on X
  • 四谷言ノ助@g_yotuya
    General

    FortiOS 7.4.12 今日現在のCVEは6個 CVE-2026-71408 CVE-2026-23573 CVE-2025-62826 CVE-2025-62675 CVE-2025-54821 CVE-2025-31514 CVE-2025-54821 CVSS 6.0 EPSS 0.15 この辺が少し懸念。

    Post summary

    The post lists six FortiOS 7.4.12 CVEs, highlighting CVSS and EPSS metrics for CVE-2025-54821 and expressing mild concern, but offers no further technical or remedial details.

    10000237
    4.3K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
OSfortinetfortipam---
Appfortinetfortiproxy---

Explore more