Medium severity6.5NVD Advisory· Published Oct 14, 2025· Updated Jun 17, 2026
CVE-2025-59921
CVE-2025-59921
Description
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version 7.1.4 and below, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to obtain sensitive data via crafted HTTP or HTTPs requests.
Affected products
4cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*range: >=6.2.0,<7.1.5
- cpe:2.3:a:fortinet:fortiadc:7.4.0:*:*:*:*:*:*:*
- cpe:2.3:h:fortinet:fortiadc:7.4.0:*:*:*:*:*:*:*range: 7.4.0
- Range: 7.4.0, 7.2.3 and below, 7.1.4 and below, 7.0 all versions, 6.2 all versions
Patches
Vulnerability mechanics
References
1- fortiguard.fortinet.com/psirt/FG-IR-23-434nvdBroken Link
News mentions
0No linked articles in our index yet.