CVE-2025-46775: Credential leakage through debug commands
A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands.
Other sources
An insufficiently protected credentials vulnerability [CWE-522] in FortiExtender may allow an authenticated user to obtain administrator credentials via debug log commands.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46775?
The severity of CVE-2025-46775 is rated as critical due to its potential for exposing administrator credentials.
How do I fix CVE-2025-46775?
To fix CVE-2025-46775, update FortiExtender to version 7.6.3 or 7.4.8 for vulnerable versions.
What versions of FortiExtender are affected by CVE-2025-46775?
CVE-2025-46775 affects FortiExtender versions 7.6.0 to 7.6.1, 7.4.0 to 7.4.6, and all versions of 7.2 and 7.0.
Who is impacted by CVE-2025-46775?
Authenticated users of Fortinet FortiExtender that utilize affected versions may be impacted by CVE-2025-46775.
What type of vulnerability is CVE-2025-46775?
CVE-2025-46775 is a debug message vulnerability that reveals unnecessary information potentially allowing credential retrieval.