Home

Description

A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker with shell access to the device to connect to redis service and access its data

PUBLISHED Reserved 2025-09-18 | Published 2025-11-18 | Updated 2025-11-18 | Assigner fortinet




MEDIUM: 4.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:U/RC:R

Problem types

Improper access control

Product status

Default status
unaffected

7.6.0
affected

7.4.0 (semver)
affected

7.2.0 (semver)
affected

7.0.0 (semver)
affected

References

fortiguard.fortinet.com/psirt/FG-IR-25-843

cve.org (CVE-2025-59669)

nvd.nist.gov (CVE-2025-59669)

Download JSON