CVE-2025-67862
Description
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0 all versions may allow an authenticated admin to execute lua scripts via crafted CLI commands.
In plain language
AI Worth attentionIf you run Fortinet FortiOS or FortiProxy on one of the affected versions, an authenticated admin account could use unsafe debug access to run unwanted Lua scripts via crafted CLI commands—fixing it is recommended for a typical small business, especially if you expose management interfaces or have admin accounts you can’t strictly control.
Fortinet FortiOS (7.6.0–7.6.2, 7.4.0–7.4.7, 7.2.0–7.2.10, 7.0.0–7.0.16, and 6.4 all versions) and FortiProxy (7.6.0–7.6.3, 7.4.0–7.4.10, 7.2.0–7.2.14, and 7.0 all versions) have a CWE-1244 issue where an authenticated admin can reach unsafe debug access/state and trigger execution of Lua scripts via crafted CLI commands.
What to do now
- Check your installed versions of FortiOS and FortiProxy (System/Status for FortiOS; System information for FortiProxy).
- If you are on FortiOS 7.6.0–7.6.2, 7.4.0–7.4.7, 7.2.0–7.2.10, 7.0.0–7.0.16, or FortiOS 6.4, plan an upgrade.
- If you are on FortiProxy 7.6.0–7.6.3, 7.4.0–7.4.10, 7.2.0–7.2.14, or FortiProxy 7.0, plan an upgrade.
- Upgrade to the fixed versions listed by Fortinet: FortiOS 7.6.3 or above, 7.4.8 or above, 7.2.11 or above, 7.0.17 or above; FortiProxy 7.6.4 or above; (and per Fortinet guidance for other branches).
- Limit and review admin access: remove unused accounts, enforce strong passwords, and restrict management access to trusted networks only.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-67862 and every CVE in our database. Create a free account — no credit card required.
Create Free Account