CVE-2019-6696: Fortinet FortiOS

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage.

Affected products

  • Fortinet FortiOS: from 5.4.0, up to and including 6.0.8; version 6.2.0 only; version 6.2.1 only

Published 2020-03-15. Last modified 2026-06-17.