# CVE-2025-62439

## Summary

- **CVE ID:** CVE-2025-62439
- **Severity:** LOW
- **CVSS Score:** 3.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N/E:P/RL:X/RC:R)
- **CWE:** CWE-940
- **Published:** Feb 10, 2026
- **Last Modified:** May 12, 2026

## Description

An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions may allow an authenticated user with knowledge of FSSO policy configurations to gain unauthorized access to protected network resources via crafted requests.

## Affected Products

- Fortinet — FortiOS (7.6.0)
- Fortinet — FortiOS (7.4.0)
- Fortinet — FortiOS (7.2.0)
- Fortinet — FortiOS (7.0.0)

## References

- [CNA](https://fortiguard.fortinet.com/psirt/FG-IR-25-384)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-975644.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._