# CVE-2025-46775

## Summary

- **CVE ID:** CVE-2025-46775
- **Severity:** MEDIUM
- **CVSS Score:** 5.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:U/RC:C)
- **CWE:** CWE-1295
- **Published:** Nov 18, 2025
- **Last Modified:** Mar 13, 2026

## Description

A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands.

## Affected Products

- Fortinet — FortiExtender (7.6.0)
- Fortinet — FortiExtender (7.4.0)
- Fortinet — FortiExtender (7.2.0)
- Fortinet — FortiExtender (7.0.0)

## References

- [CNA](https://fortiguard.fortinet.com/psirt/FG-IR-25-259)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._