VYPR
Unrated severityNVD Advisory· Published Aug 12, 2025· Updated Jan 14, 2026

CVE-2024-40588

CVE-2024-40588

Description

Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions, FortiMail 6.4 all versions, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.6, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiRecorder 6.4 all versions, FortiVoice 7.0.0 through 7.0.3, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions may allow a privileged attacker to read files from the underlying filesystem via crafted CLI requests.

Affected products

5
  • Fortinet/FortiCamerav5
    cpe:2.3:a:fortinet:forticamera:2.1.4:*:*:*:*:*:*:*
    Range: 2.1.0
  • cpe:2.3:a:fortinet:fortimail:7.6.1:*:*:*:*:*:*:*
    Range: 7.6.0
  • cpe:2.3:a:fortinet:fortindr:7.6.1:*:*:*:*:*:*:*
    Range: 7.6.0
  • Fortinet/FortiRecorderv5
    cpe:2.3:a:fortinet:fortirecorder:7.2.1:*:*:*:*:*:*:*
    Range: 7.2.0
  • cpe:2.3:a:fortinet:fortivoice:7.0.3:*:*:*:*:*:*:*
    Range: 7.0.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.