SB2025111873 - Improper privilege management in Fortinet products
Published: November 18, 2025
Security Bulletin ID
SB2025111873
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper privilege management (CVE-ID: CVE-2025-54821)
The vulnerability allows a local privileged user to manipulate data.
The vulnerability exists due to improper privilege management via SSH. An authenticated administrator can bypass the trusted host policy via crafted CLI command.
Remediation
Install update from vendor's website.