CVE-2025-22859: Path Traversal
A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22859?
CVE-2025-22859 is considered a high severity vulnerability that could allow remote unauthenticated attackers to perform arbitrary file writes.
How do I fix CVE-2025-22859?
To fix CVE-2025-22859, users should upgrade to FortiClientEMS and FortiClientEMS Cloud versions 7.4.2 or later.
Who is affected by CVE-2025-22859?
CVE-2025-22859 affects users of FortiClientEMS versions 7.4.0 through 7.4.1 and FortiClientEMS Cloud versions 7.4.0 through 7.4.1.
What types of attacks are possible with CVE-2025-22859?
CVE-2025-22859 allows an attacker to exploit relative path traversal to perform limited arbitrary file writes on the affected systems.
Is authentication required to exploit CVE-2025-22859?
No, CVE-2025-22859 can be exploited by remote unauthenticated attackers.