Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2820 articles · 164216 vulns · 37/41 feeds (7d)
← Back to list
5.4
CVE-2025-61624EXPLOITEDPATCHED
fortinet · fortios

CVE-2025-61624: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet For

Description

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSwitchManager 7.2.0 through 7.2.7, FortiSwitchManager 7.0.0 through 7.0.6 may allow an authenticated attacker with admin profile and at least read-write permissions to write or delete arbitrary files via specific CLI commands.

Affected Products

VendorProductVersions
fortinetfortios7.6.0, 7.4.0, 7.2.0, 7.0.0, 6.4.0, 7.6.0, 7.4.0, 7.2.0, 7.0.0, 7.2.0, 7.0.0, 1.7.0, 1.6.0, 1.5.0, 1.4.0, 1.3.0, 1.2.0, 1.1.0, 1.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
fortinetfortiproxymitre_affected90%
fortinetfortiswitchmanagermitre_affected90%
fortinetfortipammitre_affected90%
fortinetfortiswitchcert_advisory90%
fortinetfortioscert_advisory90%

References

  • https://fortiguard.fortinet.com/psirt/FG-IR-26-122

Related News (6 articles)

Tier D
BleepingComputer1d ago
Critical Fortinet FortiSandbox flaws now exploited in attacks
→ No new info (linked only)
Tier B
CERT-FR58d ago
Bulletin d'actualité CERTFR-2026-ACT-018 (20 avril 2026)
→ No new info (linked only)
Tier B
BSI Advisories63d ago
[NEU] [mittel] Fortinet FortiOS, FortiProxy und FortiSwitch: Schwachstelle ermöglicht Manipulation von Dateien
→ No new info (linked only)
Tier B
CERT-FR63d ago
Multiples vulnérabilités dans les produits Fortinet (15 avril 2026)
→ No new info (linked only)
Tier C
VulDB63d ago
CVE-2025-61624 | Fortinet FortiOS/FortiProxy/FortiSwitchManager/FortiPAM path traversal (FG-IR-26-122)
→ No new info (linked only)
Tier A
Fortinet PSIRT64d ago
Path Traversal in CLI
→ No new info (linked only)
CVSS 3.15.4 MEDIUM
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H/E:P/RL:O/RC:C
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
7.6.5
CWECWE-22
PublishedApr 14, 2026
Last enriched63d agov2
Trending Score56
Source articles6
Independent5
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-39808EXPKEV
CVE-2026-39808: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
Trending: 152
CRITICALCVE-2026-39813EXPKEV
CVE-2026-39813: A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.
Trending: 147
CRITICALCVE-2026-25089EXP
CVE-2026-25089: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
Trending: 94
CRITICALCVE-2026-35616EXPKEV
CVE-2026-35616: A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
Trending: 71
CRITICALCVE-2026-26083
CVE-2026-26083: A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, Fo
Trending: 66

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 14, 2026
Discovered by ZDM
Apr 14, 2026
Updated: affectedVersions, severity, exploitAvailable, activelyExploited, patchAvailable
Apr 14, 2026
Actively Exploited
Apr 14, 2026
Exploit Available
Apr 14, 2026
Patch Available
Apr 14, 2026

Version History

v2
Last enriched 63d ago
v2Tier A63d ago

Updated affected versions with new fixed release numbers, changed severity to HIGH, and marked exploit as available and actively exploited.

affectedVersionsseverityexploitAvailableactivelyExploitedpatchAvailable
via Fortinet PSIRT
v163d ago

Initial creation