CVE-2025-54822 Overview
CVE-2025-54822 is an improper authorization vulnerability [CWE-285] affecting Fortinet FortiOS and FortiProxy. The flaw allows an authenticated attacker to access static files belonging to other Virtual Domains (VDOMs) through crafted HTTP or HTTPS requests. VDOM segmentation is a core multi-tenancy feature in Fortinet appliances, and this vulnerability weakens the isolation boundary between administrative domains. The issue affects multiple FortiOS 7.x branches and all supported FortiProxy 2.0, 7.0, 7.2, and 7.4 releases through 7.4.8.
Critical Impact
An authenticated user in one VDOM can read static files from other VDOMs, undermining tenant isolation on shared Fortinet appliances.
Affected Products
- Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.8, and 7.0.0 through 7.0.11
- Fortinet FortiProxy 7.4.0 through 7.4.8, all 7.2 versions, and all 7.0 versions
- Fortinet FortiProxy 2.0 all versions
Discovery Timeline
- 2025-10-14 - CVE-2025-54822 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-54822
Vulnerability Analysis
The vulnerability stems from insufficient authorization checks on requests targeting static files served by the FortiOS and FortiProxy web interface. VDOMs are designed to provide administrative and traffic isolation between logical instances on a single appliance. The affected code paths do not consistently validate that a requesting user's VDOM context matches the VDOM owning the requested static resource. An authenticated attacker with access to any VDOM can therefore reach static content associated with other VDOMs. Exploitation requires valid credentials on the target device and network reachability to the management interface. The impact is limited to confidentiality of static file contents; the flaw does not directly permit data modification or service disruption.
Root Cause
The root cause is a missing or incomplete authorization check [CWE-285] on the HTTP/HTTPS request handler responsible for serving static files. The handler resolves file paths without enforcing that the requester's VDOM scope owns the resource, breaking the tenant boundary that VDOMs are intended to enforce.
Attack Vector
The attack is network-based and requires prior authentication with low privileges. An attacker sends crafted HTTP or HTTPS requests to the appliance web interface, referencing static file paths associated with a VDOM other than their own. Because user interaction is not required and complexity is low, any authenticated tenant, including a compromised low-privilege account, can enumerate and retrieve cross-VDOM static content. Refer to the Fortinet Security Advisory FG-IR-25-684 for vendor-provided technical details.
Detection Methods for CVE-2025-54822
Indicators of Compromise
- HTTP or HTTPS requests to the FortiOS or FortiProxy management interface referencing static file paths outside the requester's assigned VDOM.
- Repeated 200 OK responses to authenticated requests from accounts scoped to a single VDOM but retrieving resources associated with multiple VDOMs.
- Unusual enumeration patterns targeting static asset endpoints from low-privilege administrative accounts.
Detection Strategies
- Review FortiOS and FortiProxy administrative access logs for cross-VDOM URI patterns tied to a single authenticated session.
- Correlate authentication events with subsequent static-file requests to identify accounts fetching resources outside their assigned scope.
- Baseline normal administrative usage per VDOM and alert on deviations, particularly bulk retrieval of static content.
Monitoring Recommendations
- Forward FortiOS and FortiProxy syslog and admin audit logs to a central SIEM for long-term analysis.
- Alert on authenticated web-interface requests originating from unexpected source IP ranges or outside normal administrative hours.
- Monitor for new or unexpected administrative accounts, especially those scoped to VDOMs with sensitive tenants.
How to Mitigate CVE-2025-54822
Immediate Actions Required
- Apply the fixed FortiOS and FortiProxy releases identified in FG-IR-25-684 as soon as maintenance windows allow.
- Restrict administrative interface exposure to trusted management networks and enforce multi-factor authentication for all admin accounts.
- Audit VDOM administrator accounts and remove unused or over-scoped credentials.
Patch Information
Fortinet has published fixed versions and remediation guidance in security advisory FG-IR-25-684. Administrators should consult the advisory for the exact fixed builds corresponding to each affected FortiOS 7.0, 7.2, and 7.4 branch and for FortiProxy 2.0, 7.0, 7.2, and 7.4.
Workarounds
- Limit access to the FortiOS and FortiProxy web management interface using trusthost entries so that only known administrative sources can authenticate.
- Disable HTTP and HTTPS administrative access on interfaces exposed to untrusted networks until patches are applied.
- Segregate high-sensitivity tenants onto dedicated appliances where feasible to reduce blast radius of cross-VDOM disclosure.
# Configuration example: restrict admin access to trusted hosts
config system admin
edit "admin"
set trusthost1 10.0.0.0 255.255.255.0
set trusthost2 192.168.10.0 255.255.255.0
next
end
# Disable HTTP/HTTPS admin access on an untrusted interface
config system interface
edit "wan1"
unset allowaccess
next
end
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.