CVE Tools

Description

An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0 all versions may allow an authenticated admin to execute lua scripts via crafted CLI commands.

In plain language

AI Worth attention

If you run Fortinet FortiOS or FortiProxy on one of the affected versions, an authenticated admin account could use unsafe debug access to run unwanted Lua scripts via crafted CLI commands—fixing it is recommended for a typical small business, especially if you expose management interfaces or have admin accounts you can’t strictly control.

Executive summary

Fortinet FortiOS (7.6.0–7.6.2, 7.4.0–7.4.7, 7.2.0–7.2.10, 7.0.0–7.0.16, and 6.4 all versions) and FortiProxy (7.6.0–7.6.3, 7.4.0–7.4.10, 7.2.0–7.2.14, and 7.0 all versions) have a CWE-1244 issue where an authenticated admin can reach unsafe debug access/state and trigger execution of Lua scripts via crafted CLI commands.

If affected, business impact
Device takeover by admin abuseNetwork disruptionService outage riskSensitive configuration exposure

What to do now

  1. Check your installed versions of FortiOS and FortiProxy (System/Status for FortiOS; System information for FortiProxy).
  2. If you are on FortiOS 7.6.0–7.6.2, 7.4.0–7.4.7, 7.2.0–7.2.10, 7.0.0–7.0.16, or FortiOS 6.4, plan an upgrade.
  3. If you are on FortiProxy 7.6.0–7.6.3, 7.4.0–7.4.10, 7.2.0–7.2.14, or FortiProxy 7.0, plan an upgrade.
  4. Upgrade to the fixed versions listed by Fortinet: FortiOS 7.6.3 or above, 7.4.8 or above, 7.2.11 or above, 7.0.17 or above; FortiProxy 7.6.4 or above; (and per Fortinet guidance for other branches).
  5. Limit and review admin access: remove unused accounts, enforce strong passwords, and restrict management access to trusted networks only.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:LAC:LPR:HUI:NS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:HPrivileges Required
High
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 2 more affected products View all →

Exploitability

Official Patch Available

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2025-67862 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows