CVE-2025-59921: Infoleak
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version 7.1.4 and below, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to obtain sensitive data via crafted HTTP or HTTPs requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59921?
The severity of CVE-2025-59921 is categorized as critical due to the potential exposure of sensitive information.
How do I fix CVE-2025-59921?
To fix CVE-2025-59921, update Fortinet FortiADC to the latest versions that address this vulnerability.
What versions of Fortinet FortiADC are affected by CVE-2025-59921?
CVE-2025-59921 affects Fortinet FortiADC versions 7.4.0, 7.2.3 and below, 7.1.4 and below, 7.0 all versions, and 6.2 all versions.
What types of attacks could exploit CVE-2025-59921?
CVE-2025-59921 could be exploited by authenticated attackers through crafted HTTP or HTTPS requests to obtain sensitive data.
Is it possible to mitigate CVE-2025-59921 without updating?
Mitigating CVE-2025-59921 without updating is not advisable, as the best defense is to apply firmware updates to secure the affected systems.