CVE-2025-48418: Privilege escalation using undocumented CLI command
A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAnalyzer Cloud 7.2.1 through 7.2.10, FortiAnalyzer Cloud 7.0.1 through 7.0.14, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.0 through 7.2.10, FortiManager 7.0.0 through 7.0.14, FortiManager 6.4 all versions, FortiManager Cloud 7.6.2 through 7.6.3, FortiManager Cloud 7.4.1 through 7.4.7, FortiManager Cloud 7.2.1 through 7.2.10, FortiManager Cloud 7.0.1 through 7.0.14, FortiManager Cloud 6.4 all versions may allow a remote authenticated read-only admin with CLI access to escalate their privilege via use of a hidden command.
Other sources
An Inclusion of Undocumented Features [CWE-1242] in FortiManager and FortiAnalyzer CLI may allow a remote authenticated read-only admin with CLI access to escalate their privilege via use of a hidden command.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48418?
The severity of CVE-2025-48418 is considered critical, as it allows for privilege escalation through undocumented CLI commands.
How do I fix CVE-2025-48418?
To fix CVE-2025-48418, upgrade to FortiAnalyzer version 7.6.4 or higher, or apply applicable patches for other affected versions.
Which Fortinet products are affected by CVE-2025-48418?
CVE-2025-48418 affects multiple versions of FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, and FortiManager Cloud.
What versions of Fortinet FortiAnalyzer are impacted by CVE-2025-48418?
Fortinet FortiAnalyzer versions 6.4, 7.0.0 through 7.0.14, 7.2.0 through 7.2.10, 7.4.0 through 7.4.7, and 7.6.0 through 7.6.3 are impacted.
What should I do if I cannot update my system to mitigate CVE-2025-48418?
If you cannot update your system, implement strict access controls and monitor logs for suspicious CLI commands to mitigate CVE-2025-48418.