CVE-2025-58693

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker

Severity
Medium 5.7
CVSS 3.1
Exploited
Not listed
EPSS
0.006
45.4th percentile
Discovered by
Not disclosed
Published
Jan 13, 2026
Assigned by fortinet

Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.

Weakness: CWE-22

Affected products

Vendor Product Category Matched by
Fortinet FortiVoice Other Products cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiVoice

Vendor remediation

Upgrade to FortiVoice version 7.2.3 or above Upgrade to FortiVoice version 7.0.8 or above