CVE-2025-67862CWE-1244

An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0…

Medium · published June 9, 2026

CVSS v3.1
6.0
EPSS
0%
Percentile
4.4
In the wild
Unconfirmed
What it is

An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0 all versions may allow an authenticated admin to execute lua scripts via crafted CLI commands.

The record
Technical detail
CVSS v3.1
6.0 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CVSS v4.0
Not supplied
EPSS
0.00149 · 4.4th percentile
Weakness
CWE-1244 · Internal Asset Exposed to Unsafe Debug Access Level or State
Published
2026-06-09T14:27Z
EPSS history
Timeline
  • 09 JUN 14:27Z
    An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0…
    cvelistv5