An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.
Advisories

No advisories yet.

Fixes

Solution

Upgrade to FortiPortal version 7.4.6 or above


Workaround

No workaround given by the vendor.

History

Tue, 09 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*

Tue, 09 Dec 2025 17:45:00 +0000

Type Values Removed Values Added
Description An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.
First Time appeared Fortinet
Fortinet fortiportal
Weaknesses CWE-863
CPEs cpe:2.3:a:fortinet:fortiportal:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:7.4.5:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiportal
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H/E:P/RL:X/RC:C'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2025-12-09T20:43:14.142Z

Reserved: 2025-07-31T08:07:23.557Z

Link: CVE-2025-54838

cve-icon Vulnrichment

Updated: 2025-12-09T20:20:46.758Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-09T18:15:54.133

Modified: 2025-12-09T20:04:58.327

Link: CVE-2025-54838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses