Skip to main content
Vulnerability Database/CVE-2025-54822

CVE-2025-54822: Fortinet FortiOS Auth Bypass Vulnerability

CVE-2025-54822 is an authentication bypass flaw in Fortinet FortiOS that allows authenticated attackers to access static files across VDOMs. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2025-54822 Overview

CVE-2025-54822 is an improper authorization vulnerability [CWE-285] affecting Fortinet FortiOS and FortiProxy. The flaw allows an authenticated attacker to access static files belonging to other Virtual Domains (VDOMs) through crafted HTTP or HTTPS requests. VDOM segmentation is a core multi-tenancy feature in Fortinet appliances, and this vulnerability weakens the isolation boundary between administrative domains. The issue affects multiple FortiOS 7.x branches and all supported FortiProxy 2.0, 7.0, 7.2, and 7.4 releases through 7.4.8.

Critical Impact

An authenticated user in one VDOM can read static files from other VDOMs, undermining tenant isolation on shared Fortinet appliances.

Affected Products

  • Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.8, and 7.0.0 through 7.0.11
  • Fortinet FortiProxy 7.4.0 through 7.4.8, all 7.2 versions, and all 7.0 versions
  • Fortinet FortiProxy 2.0 all versions

Discovery Timeline

  • 2025-10-14 - CVE-2025-54822 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-54822

Vulnerability Analysis

The vulnerability stems from insufficient authorization checks on requests targeting static files served by the FortiOS and FortiProxy web interface. VDOMs are designed to provide administrative and traffic isolation between logical instances on a single appliance. The affected code paths do not consistently validate that a requesting user's VDOM context matches the VDOM owning the requested static resource. An authenticated attacker with access to any VDOM can therefore reach static content associated with other VDOMs. Exploitation requires valid credentials on the target device and network reachability to the management interface. The impact is limited to confidentiality of static file contents; the flaw does not directly permit data modification or service disruption.

Root Cause

The root cause is a missing or incomplete authorization check [CWE-285] on the HTTP/HTTPS request handler responsible for serving static files. The handler resolves file paths without enforcing that the requester's VDOM scope owns the resource, breaking the tenant boundary that VDOMs are intended to enforce.

Attack Vector

The attack is network-based and requires prior authentication with low privileges. An attacker sends crafted HTTP or HTTPS requests to the appliance web interface, referencing static file paths associated with a VDOM other than their own. Because user interaction is not required and complexity is low, any authenticated tenant, including a compromised low-privilege account, can enumerate and retrieve cross-VDOM static content. Refer to the Fortinet Security Advisory FG-IR-25-684 for vendor-provided technical details.

Detection Methods for CVE-2025-54822

Indicators of Compromise

  • HTTP or HTTPS requests to the FortiOS or FortiProxy management interface referencing static file paths outside the requester's assigned VDOM.
  • Repeated 200 OK responses to authenticated requests from accounts scoped to a single VDOM but retrieving resources associated with multiple VDOMs.
  • Unusual enumeration patterns targeting static asset endpoints from low-privilege administrative accounts.

Detection Strategies

  • Review FortiOS and FortiProxy administrative access logs for cross-VDOM URI patterns tied to a single authenticated session.
  • Correlate authentication events with subsequent static-file requests to identify accounts fetching resources outside their assigned scope.
  • Baseline normal administrative usage per VDOM and alert on deviations, particularly bulk retrieval of static content.

Monitoring Recommendations

  • Forward FortiOS and FortiProxy syslog and admin audit logs to a central SIEM for long-term analysis.
  • Alert on authenticated web-interface requests originating from unexpected source IP ranges or outside normal administrative hours.
  • Monitor for new or unexpected administrative accounts, especially those scoped to VDOMs with sensitive tenants.

How to Mitigate CVE-2025-54822

Immediate Actions Required

  • Apply the fixed FortiOS and FortiProxy releases identified in FG-IR-25-684 as soon as maintenance windows allow.
  • Restrict administrative interface exposure to trusted management networks and enforce multi-factor authentication for all admin accounts.
  • Audit VDOM administrator accounts and remove unused or over-scoped credentials.

Patch Information

Fortinet has published fixed versions and remediation guidance in security advisory FG-IR-25-684. Administrators should consult the advisory for the exact fixed builds corresponding to each affected FortiOS 7.0, 7.2, and 7.4 branch and for FortiProxy 2.0, 7.0, 7.2, and 7.4.

Workarounds

  • Limit access to the FortiOS and FortiProxy web management interface using trusthost entries so that only known administrative sources can authenticate.
  • Disable HTTP and HTTPS administrative access on interfaces exposed to untrusted networks until patches are applied.
  • Segregate high-sensitivity tenants onto dedicated appliances where feasible to reduce blast radius of cross-VDOM disclosure.
bash
# Configuration example: restrict admin access to trusted hosts
config system admin
    edit "admin"
        set trusthost1 10.0.0.0 255.255.255.0
        set trusthost2 192.168.10.0 255.255.255.0
    next
end

# Disable HTTP/HTTPS admin access on an untrusted interface
config system interface
    edit "wan1"
        unset allowaccess
    next
end

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.