CVE-2025-53379 – FortiAuthenticator

CVSS 7.5 IMPORTANT High with EoP or RCE – Expedited Deployment

“A single crafted request should never expose sensitive information from a trusted authentication system.”

Fortinet has released an update for FortiAuthenticator to address CVE-2025-53379, a high-severity out-of-bounds read vulnerability affecting FortiAuthenticator 6.6.0 through 6.6.2 and all versions of the 6.5 release. The flaw could allow a remote, unauthenticated attacker to retrieve sensitive information by sending a specially crafted request. The vulnerability is associated with CWE-125 (Out-of-bounds Read).

The CVSS score is 7.0, which is High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with this vulnerability.

Key Details

Affected Product
Fortinet Fortiauthenticator
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-125
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.