CVE-2026-25689: Medium severity Fortinet FortiDeceptor vulnerability
An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.2.0, FortiDeceptor 6.0 all versions, FortiDeceptor 5.3 all versions, FortiDeceptor 5.2 all versions, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDeceptor 4.3 all versions, FortiDeceptor 4.2 all versions, FortiDeceptor 4.1 all versions, FortiDeceptor 4.0 all versions may allow a privileged attacker with super-admin profile and CLI access to delete sensitive files via crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25689?
CVE-2026-25689 is rated as a medium severity vulnerability due to its potential impact on system security.
How do I fix CVE-2026-25689?
To fix CVE-2026-25689, upgrade to FortiDeceptor version 6.2.1 or later, or apply the recommended security patches.
What systems are affected by CVE-2026-25689?
CVE-2026-25689 affects all versions of FortiDeceptor from 5.0 up to 6.2.0.
What type of vulnerability is CVE-2026-25689?
CVE-2026-25689 is an improper neutralization of argument delimiters, commonly referred to as an argument injection vulnerability.
Can CVE-2026-25689 be exploited remotely?
Yes, CVE-2026-25689 can potentially be exploited remotely by an attacker through crafted commands.