CVE-2025-25252
published 2025-10-14CVE-2025-25252: An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through…
PriorityP180medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
0.34%
24.5th percentile
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML record.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.4.0 < 7.0.17 | 7.0.17 |
| fortinet | fortios | 6.4.0 – 6.4.16 | — |
| fortinet | fortios | 7.0.0 – 7.0.16 | — |
| fortinet | fortios | >= 7.2.0 < 7.2.11 | 7.2.11 |
| fortinet | fortios | 7.2.0 – 7.2.10 | — |
| fortinet | fortios | >= 7.4.0 < 7.4.7 | 7.4.7 |
| fortinet | fortios | 7.4.0 – 7.4.6 | — |
| fortinet | fortios | >= 7.6.0 < 7.6.3 | 7.6.3 |
| fortinet | fortios | 7.6.0 – 7.6.2 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
vulncheck6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Insufficient Session Expiration in SSLVPN using SAML authentication
vendor_fortinet·2025-10-14·CVSS 4.8
CVE-2025-25252 [MEDIUM] CWE-613 Insufficient Session Expiration in SSLVPN using SAML authentication
FG-IR-24-487: Insufficient Session Expiration in SSLVPN using SAML authentication
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML record.
CVEs: CVE-2025-25252
CWEs: CWE-613
CVSS: 4.8 (medium)
Affected products: FortiOS
GHSA
GHSA-8vxf-42v3-rc9p: An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7
ghsa_unreviewed·2025-10-14
CVE-2025-25252 [MEDIUM] CWE-613 GHSA-8vxf-42v3-rc9p: An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML record.
VulnCheck
Fortinet FortiOS Insufficient Session Expiration
vulncheck·2025·CVSS 6.5
CVE-2025-25252 [MEDIUM] Fortinet FortiOS Insufficient Session Expiration
Fortinet FortiOS Insufficient Session Expiration
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML record.
Affected: Fortinet FortiOS
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://cydome.io/maritime-cybersecurity-bulletin-september-11th-2026/
Exploit PoC: https://vulncheck.com/xdb/a5792665e6fa
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-14
Published
Exploited in the wild