CVE-2025-57823: Low severity Fortinet FortiAuthenticator vulnerability
A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57823?
The severity of CVE-2025-57823 is classified as high due to the potential for authenticated attackers to exploit the vulnerability.
How do I fix CVE-2025-57823?
To fix CVE-2025-57823, update Fortinet FortiAuthenticator to the latest version available, which addresses this vulnerability.
What systems are affected by CVE-2025-57823?
CVE-2025-57823 affects Fortinet FortiAuthenticator versions 6.3, 6.4, 6.5, and versions 6.6.0 through 6.6.6.
What type of vulnerability is CVE-2025-57823?
CVE-2025-57823 is a direct request or 'forced browsing' vulnerability that can be exploited by authenticated attackers.
Are there any known exploitations of CVE-2025-57823?
As of now, there have been no confirmed reports of active exploitations of CVE-2025-57823 in the wild.