CVE-2025-58693
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker
Severity
Medium 5.7
CVSS 3.1
Exploited
Not listed
EPSS
0.006
45.4th percentile
Discovered by
Not disclosed
Published
Jan 13, 2026
Assigned by fortinet
Description
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
Weakness: CWE-22
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiVoice | Other Products | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiVoice
Vendor remediation
Upgrade to FortiVoice version 7.2.3 or above Upgrade to FortiVoice version 7.0.8 or above