CVE-2025-25255: Fortinet FortiOS

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0.1 through 7.0.22 may allow an unauthenticated proxy user to bypass the domain fronting protection feature via crafted HTTP requests.

Affected products

  • Fortinet FortiOS: from 7.6.0, before 7.6.4 (fixed in 7.6.4)
  • Fortinet FortiProxy: from 7.0.1, before 7.6.4 (fixed in 7.6.4)

Published 2025-10-14. Last modified 2026-06-17.