CVE-2025-53845: Fortinet Fortianalyzer

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the device's health and status, or cause a denial of service via crafted OFTP requests.

Affected products

  • Fortinet Fortianalyzer: from 6.4.0, before 7.4.7 (fixed in 7.4.7); from 7.6.0, before 7.6.4 (fixed in 7.6.4)

Published 2025-10-14. Last modified 2026-10-08.