CVE-2025-46775
published 2025-11-18CVE-2025-46775: A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.14%
3.9th percentile
A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiextender | — | — |
| fortinet | fortiextender | 7.0.0 – 7.0.5 | — |
| fortinet | fortiextender | 7.2.0 – 7.2.5 | — |
| fortinet | fortiextender | 7.4.0 – 7.4.6 | — |
| fortinet | fortiextender | 7.6.0 – 7.6.1 | — |
| fortinet | fortiextender_firmware | >= 7.0.0 < 7.4.8 | 7.4.8 |
| fortinet | fortiextender_firmware | >= 7.6.0 < 7.6.3 | 7.6.3 |
| fortinet | fortiextenderfirmware | — | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Credential leakage through debug commands
vendor_fortinet·2025-11-18·CVSS 5.5
CVE-2025-46775 [MEDIUM] CWE-1295 Credential leakage through debug commands
FG-IR-25-259: Credential leakage through debug commands
A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands.
CVEs: CVE-2025-46775
CWEs: CWE-1295
CVSS: 5.5 (medium)
Affected products: FortiExtender, FortiExtenderfirmware, Fortinet
GHSA
GHSA-6vg5-gh5c-gr5c: A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7
ghsa_unreviewed·2025-11-18
CVE-2025-46775 [MEDIUM] CWE-1295 GHSA-6vg5-gh5c-gr5c: A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7
A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-18
Published