CVE-2025-46775
A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.2
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:U/RC:C
- EPSS probability
- 0.16%
- CWE
- CWE-1295
- Published
- 2025-11-18
- Last modified
- 2026-03-13
Affected products
- Fortinet FortiExtender
- Fortinet FortiExtender
- Fortinet FortiExtender
- Fortinet FortiExtender
Weakness type
Related vulnerabilities
- CVE-2026-28811 — Apache JSPWiki: Error Handling - Reveals Error Details
- CVE-2026-48797 — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
- CVE-2025-59109 — UART Leaking Sensitive Data in dormakaba registration unit 9002
- CVE-2025-35031 — Medical Informatics Engineering Enterprise Health includes session token in debug output
- CVE-2025-42604 — Detailed Error Response Vulnerability in Meon KYC solutions
- CVE-2025-2469 — Debug Messages Revealing Unnecessary Information in GitLab
- CVE-2025-31001 — WordPress GTM Kit plugin <= 2.4.0 - Sensitive Data Exposure vulnerability
- CVE-2025-2877 — Event-driven-ansible: exposure inventory passwords in plain text when starting a rulebook activation with verbosity set to debug in eda