CVE-2025-49201
Description
A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted http requests
Summary dbcve.org
A weak authentication vulnerability in Fortinet FortiPAM and FortiSwitchManager allows unauthenticated attackers to execute arbitrary code or commands by sending specially crafted HTTP requests. The vulnerability stems from insufficient authentication controls that can be bypassed or exploited through malformed requests.
Mitigation
Apply vendor-supplied patches or upgrade to FortiPAM 1.5.1 or later and FortiSwitchManager 7.2.5 or later. Restrict administrative interface access to trusted networks until patches are applied.