CVE-2025-67862
Awaiting Analysis Awaiting Analysis - Queue
Unsafe Debug Access in FortiOS and FortiProxy

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: Fortinet, Inc.

Description
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0 all versions may allow an authenticated admin to execute lua scripts via crafted CLI commands.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-10
AI Q&A
2026-06-09
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 16 associated CPEs
Vendor Product Version / Range
fortinet fortios From 7.6.0 (inc) to 7.6.2 (inc)
fortinet fortios From 7.4.0 (inc) to 7.4.7 (inc)
fortinet fortios From 7.2.0 (inc) to 7.2.10 (inc)
fortinet fortios From 7.0.0 (inc) to 7.0.16 (inc)
fortinet fortios 6.4
fortinet fortiproxy From 7.6.0 (inc) to 7.6.3 (inc)
fortinet fortiproxy From 7.4.0 (inc) to 7.4.10 (inc)
fortinet fortiproxy From 7.2.0 (inc) to 7.2.14 (inc)
fortinet fortiproxy 7.0
fortinet fortios 7.6
fortinet fortios 7.4
fortinet fortios 7.2
fortinet fortios 7.0
fortinet fortiproxy 7.6
fortinet fortiproxy 7.4
fortinet fortiproxy 7.2
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1244 The product uses physical debug or test interfaces with support for multiple access levels, but it assigns the wrong debug access level to an internal asset, providing unintended access to the asset from untrusted debug agents.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability, identified as an Internal Asset Exposed to Unsafe Debug Access Level or State (CWE-1244), affects multiple versions of Fortinet FortiOS and FortiProxy. It allows an authenticated administrator to execute lua scripts through specially crafted command-line interface (CLI) commands. This means that someone with admin access could potentially run unauthorized scripts on the affected devices.

Impact Analysis

The vulnerability can have a significant impact because it allows an authenticated admin to execute arbitrary lua scripts, which can lead to full compromise of confidentiality, integrity, and availability of the affected system. This means sensitive data could be exposed or altered, and system operations could be disrupted.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-67862. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart