MEDIUM

CVE-2025-68686

Fortinet Fortios 2026-02-10 CVSS v3.1
CVSS
5.9
KEV

Description

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

Summary dbcve.org

This is a patch bypass vulnerability in FortiOS affecting versions 7.0 through 7.6.1. An attacker who has already achieved filesystem-level compromise through another vulnerability can bypass a previous patch for symbolic link persistency mechanisms using crafted HTTP requests, enabling unauthorized access to sensitive information.

Mitigation

Apply vendor-supplied patches when available. In the interim, restrict administrative access to trusted IPs only and monitor for anomalous HTTP requests that may indicate exploitation attempts of the symbolic link mechanism.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

29.6%
Probability of exploitation in next 30 days
98.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE