CVE-2025-58412: XSS
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiADC 8.0.0, FortiADC 7.6.0 through 7.6.3, FortiADC 7.4 all versions, FortiADC 7.2 all versions may allow attacker to execute unauthorized code or commands via crafted URL.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58412?
CVE-2025-58412 has a high severity level due to its potential for allowing unauthorized code execution.
How do I fix CVE-2025-58412?
To fix CVE-2025-58412, update Fortinet FortiADC to version 7.6.4 or later.
What type of attack does CVE-2025-58412 enable?
CVE-2025-58412 enables attackers to perform cross-site scripting (XSS) attacks via crafted URLs.
Which versions of Fortinet FortiADC are affected by CVE-2025-58412?
CVE-2025-58412 affects Fortinet FortiADC versions 8.0.0, 7.6.0 through 7.6.3, and all versions of 7.4 and 7.2.
What should I monitor for regarding CVE-2025-58412?
Monitor for unusual activity or unauthorized script injections on web pages using the affected versions of Fortinet FortiADC.