CVE-2025-54838: Fortinet Fortiportal

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.

Affected products

  • Fortinet Fortiportal: from 7.4.0, up to and including 7.4.5

Published 2025-12-09. Last modified 2026-06-17.