CVE-2025-68686: SSL-VPN Symlink Persistence Patch Bypass
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
Other sources
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
— NVD
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiOS SSL-VPNto a version that resolves this vulnerability.Fixed in 7.4.7 - Upgrade
Upgrade
Fortinet FortiOS SSL-VPNto a version that resolves this vulnerability.Fixed in 7.6.2 - Compensating control
Apply mitigations in accordance with vendor instructions (per CISA BOD 26-04 Prioritizing Security Updates Based on Risk and CISA “Forensics Triage Requirements” guidance); if mitigations are unavailable, discontinue use of the product.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68686?
CVE-2025-68686 has a high severity rating due to its potential to expose sensitive information to unauthorized actors.
How do I fix CVE-2025-68686?
To fix CVE-2025-68686, upgrade FortiOS to version 7.6.2 or 7.4.7 or higher, depending on your current version.
What versions of FortiOS are affected by CVE-2025-68686?
CVE-2025-68686 affects FortiOS versions 7.6.0 to 7.6.1 and 7.4.0 to 7.4.6, along with earlier versions of the 7.2 and 7.0 series.
Can an attacker exploit CVE-2025-68686 without authentication?
Yes, a remote unauthenticated attacker can exploit CVE-2025-68686 to bypass security measures and access sensitive information.
What type of vulnerability is CVE-2025-68686?
CVE-2025-68686 is categorized as an exposure of sensitive information vulnerability, specifically related to a patch bypass in FortiOS SSL-VPN.