CVE-2025-60024: Path Traversal
Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged authenticated attacker to write arbitrary files via specifically HTTP or HTTPS commands
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60024?
CVE-2025-60024 has been classified as a high severity vulnerability due to its potential for arbitrary file writing by privileged authenticated attackers.
How can an attacker exploit CVE-2025-60024?
An attacker can exploit CVE-2025-60024 through specifically crafted HTTP requests that leverage path traversal techniques to write files in restricted directories.
What versions of Fortinet FortiVoice are affected by CVE-2025-60024?
CVE-2025-60024 affects FortiVoice versions 7.2.0 to 7.2.2 and 7.0.0 to 7.0.7.
How do I fix CVE-2025-60024?
To fix CVE-2025-60024, Fortinet recommends upgrading FortiVoice to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2025-60024 classified as?
CVE-2025-60024 is classified as a 'Path Traversal' vulnerability, which is categorized under CWE-22.