cbcvebase.
CVE-2025-25252
published 2025-10-14

CVE-2025-25252: An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through…

PriorityP339medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.28%
19.7th percentile
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML record.

Affected

10 ranges
VendorProductVersion rangeFixed in
fortinetfortios
fortinetfortios>= 6.4.0 < 7.0.177.0.17
fortinetfortios6.4.0 – 6.4.16
fortinetfortios7.0.0 – 7.0.16
fortinetfortios>= 7.2.0 < 7.2.117.2.11
fortinetfortios7.2.0 – 7.2.10
fortinetfortios>= 7.4.0 < 7.4.77.4.7
fortinetfortios7.4.0 – 7.4.6
fortinetfortios>= 7.6.0 < 7.6.37.6.3
fortinetfortios7.6.0 – 7.6.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.