CVE-2025-46775
MEDIUMDescription
A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands.
Is your site exposed to CVE-2025-46775?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| fortinet | fortiextender_firmware |
| fortinet | fortiextender_firmware |
| fortinet | fortiextender |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-46775? +
How severe is CVE-2025-46775? +
What products are affected by CVE-2025-46775? +
How do I check if I'm vulnerable to CVE-2025-46775? +
Related Vulnerabilities
This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker …
Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the …
ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from environment variables in error log. This …
Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows …
Debug Messages Revealing Unnecessary Information vulnerability in TLA Media GTM Kit gtm-kit allows Retrieve Embedded Sensitive Data.This issue affects GTM …
C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the …