CVE-2025-61624: Path Traversal in CLI
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] in the command line interpreter of FortiOS, FortiPAM, FortiProxy and FortiSwitchManager may allow a privileged attacker to achieve arbitrary write or delete files via specifically crafted arguments to existing commands.
Other sources
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSwitchManager 7.2.0 through 7.2.7, FortiSwitchManager 7.0.0 through 7.0.6 may allow an authenticated attacker with admin profile and at least read-write permissions to write or delete arbitrary files via specific CLI commands.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 8.0.0 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.5 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.10 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.5 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.12 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.8.0 - Upgrade
Upgrade
FortiPAMto a version that resolves this vulnerability.Fixed in 1.7.1 - Upgrade
Upgrade
FortiSwitchto a version that resolves this vulnerability.Fixed in 8.0.0 - Upgrade
Upgrade
FortiSwitchto a version that resolves this vulnerability.Fixed in 7.6.5 - Upgrade
Upgrade
FortiSwitchto a version that resolves this vulnerability.Fixed in 7.4.9 - Upgrade
Upgrade
FortiSwitchManagerto a version that resolves this vulnerability.Fixed in 7.2.8 - Upgrade
Upgrade
FortiSwitchManagerto a version that resolves this vulnerability.Fixed in 7.0.7 - Operational
FortiSASE was remediated in version 25.4.b; customers do not need to perform any action.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61624?
CVE-2025-61624 is considered a critical vulnerability due to its potential for arbitrary file write and delete operations.
How do I fix CVE-2025-61624?
To remediate CVE-2025-61624, update FortiOS to version 7.6.5 or later, and update FortiPAM, FortiProxy, and FortiSwitchManager as per the respective version requirements.
What products are affected by CVE-2025-61624?
CVE-2025-61624 affects FortiOS, FortiPAM, FortiProxy, and FortiSwitchManager across various versions.
What type of vulnerability is CVE-2025-61624?
CVE-2025-61624 is classified as a Path Traversal vulnerability, allowing unauthorized file access.
Who is at risk from CVE-2025-61624?
Privileged attackers who can exploit CVE-2025-61624 may gain the ability to manipulate system files on affected devices.