CVE-2025-22254: Privilege escalation in GUI websocket module
An Improper Privilege Management vulnerability [CWE-269] affecting FortiOS, FortiProxy & FortiWeb may allow an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module.
Other sources
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiWeb 7.6.0 through 7.6.1, FortiWeb 7.4.0 through 7.4.6 allows an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22254?
CVE-2025-22254 has been assessed with a high severity due to improper privilege management vulnerabilities.
How do I fix CVE-2025-22254?
To fix CVE-2025-22254, upgrade FortiOS, FortiProxy, or FortiWeb to the appropriate remedied version as specified by Fortinet.
Which versions are affected by CVE-2025-22254?
CVE-2025-22254 affects FortiOS versions 6.4.0 through 7.6.1, FortiProxy versions 7.6.0 through 7.6.1, and FortiWeb versions 7.6.0 through 7.6.1.
Is CVE-2025-22254 a critical vulnerability?
Yes, CVE-2025-22254 is considered critical due to its potential impact on system privilege management.
Who is affected by CVE-2025-22254?
Organizations using vulnerable versions of Fortinet's FortiOS, FortiProxy, and FortiWeb are affected by CVE-2025-22254.