CVE-2025-59921

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version 7.1.4 and below, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to obtain sensitive data via crafted HTTP or HTTPs requests.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiadc:7.4.0:*:*:*:*:*:*:*

History

16 Oct 2025, 14:47

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Fortinet fortiadc
Fortinet
References () https://fortiguard.fortinet.com/psirt/FG-IR-23-434 - () https://fortiguard.fortinet.com/psirt/FG-IR-23-434 - Broken Link
CPE cpe:2.3:a:fortinet:fortiadc:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*

14 Oct 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 16:15

Updated : 2025-10-16 14:47


NVD link : CVE-2025-59921

Mitre link : CVE-2025-59921

CVE.ORG link : CVE-2025-59921


JSON object : View

Products Affected

fortinet

  • fortiadc
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo