CVE-2025-58693: Path Traversal
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58693?
CVE-2025-58693 is classified as a high severity vulnerability due to its potential for allowing privileged attackers to delete critical files.
How do I fix CVE-2025-58693?
To fix CVE-2025-58693, update Fortinet FortiVoice to version 7.2.3 or later and ensure proper file access controls are implemented.
Who is affected by CVE-2025-58693?
CVE-2025-58693 affects users running Fortinet FortiVoice versions from 7.0.0 to 7.0.7 and 7.2.0 to 7.2.2.
What type of attack does CVE-2025-58693 enable?
CVE-2025-58693 enables a path traversal attack, allowing attackers to manipulate file paths and potentially delete files.
What is the potential impact of exploiting CVE-2025-58693?
Exploiting CVE-2025-58693 can result in unauthorized file deletion, leading to data loss and service disruption.