CVE-2025-54838

An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.

Severity
Medium 6.4
CVSS 3.1
Exploited
Not listed
EPSS
0.003
23.5th percentile
Discovered by
Vendor
Vendor advisory field
Published
Dec 9, 2025
Assigned by fortinet

Description

An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.

Weakness: CWE-863

Affected products

Vendor Product Category Matched by
Fortinet FortiPortal Network & Security Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiPortal

Credit

Internally discovered and reported by Hisham AboulMakarem of Fortinet Systems Engineer team.

Vendor remediation

Upgrade to FortiPortal version 7.4.6 or above

Something wrong here?