An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.
Advisories

No advisories yet.

Fixes

Solution

Upgrade to FortiPortal version 7.4.6 or above


Workaround

No workaround given by the vendor.

History

Wed, 10 Dec 2025 06:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 05:15:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*

Wed, 10 Dec 2025 02:45:00 +0900

Type Values Removed Values Added
Description An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.
First Time appeared Fortinet
Fortinet fortiportal
Weaknesses CWE-863
CPEs cpe:2.3:a:fortinet:fortiportal:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiportal:7.4.5:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiportal
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H/E:P/RL:X/RC:C'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published:

Updated: 2026-01-14T09:17:55.729Z

Reserved: 2025-07-31T08:07:23.557Z

Link: CVE-2025-54838

cve-icon Vulnrichment

Updated: 2025-12-09T20:20:46.758Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-09T18:15:54.133

Modified: 2025-12-09T20:04:58.327

Link: CVE-2025-54838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses