CVE-2025-46775

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/11/2025
Last modified:
20/11/2025

Description

A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fortinet:fortiextender_firmware:*:*:*:*:*:*:*:* 7.0.0 (including) 7.4.8 (excluding)
cpe:2.3:o:fortinet:fortiextender_firmware:*:*:*:*:*:*:*:* 7.6.0 (including) 7.6.3 (excluding)
cpe:2.3:h:fortinet:fortiextender:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools