CVE-2024-40588: Fortinet Forticamera Firmware
Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions, FortiMail 6.4 all versions, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.6, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiRecorder 6.4 all versions, FortiVoice 7.0.0 through 7.0.3, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions may allow a privileged attacker to read files from the underlying filesystem via crafted CLI requests.
Affected products
- Fortinet Forticamera Firmware: from 2.0.0, up to and including 2.1.4
- Fortinet FortiMail: from 6.4.0, before 7.4.4 (fixed in 7.4.4); from 7.6.0, before 7.6.2 (fixed in 7.6.2)
- Fortinet Fortindr: from 7.0.0, before 7.4.7 (fixed in 7.4.7); from 7.6.0, before 7.6.2 (fixed in 7.6.2)
- Fortinet Fortirecorder: from 6.4.0, before 7.0.5 (fixed in 7.0.5); from 7.2.0, before 7.2.2 (fixed in 7.2.2)
- Fortinet Fortivoice: from 6.0.0, before 6.4.10 (fixed in 6.4.10); from 7.0.0, before 7.0.5 (fixed in 7.0.5)
Published 2025-08-12. Last modified 2026-06-17.