SB2025111870 - Insufficiently protected credentials in FortiExtender



SB2025111870 - Insufficiently protected credentials in FortiExtender

Published: November 18, 2025

Security Bulletin ID SB2025111870
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Insufficiently protected credentials (CVE-ID: CVE-2025-46775)

The vulnerability allows a local authenticated user to gain access to sensitive information.

The vulnerability exists due to insufficiently protected credentials. An authenticated user can obtain administrator credentials via debug log commands.


Remediation

Install update from vendor's website.