What is CVE-2025-68686?
This vulnerability exists in Fortinet FortiOS and allows bypassing the patch developed for the symbolic link persistency mechanism. A remote unauthenticated attacker can gain unauthorized access to sensitive information via crafted HTTP requests. It is recommended to apply the latest security updates provided by Fortinet on affected systems.
Azərbaycanca: Bu zəiflik Fortinet FortiOS əməliyyat sistemində aşkarlanıb və simvolik keçid (symbolic link) mexanizmi üçün hazırlanmış yamaqdan yan keçməyə imkan verir. Uzaqdan autentifikasiya olunmamış hücumçu xüsusi HTTP sorğuları vasitəsilə həssas məlumatlara icazəsiz giriş əldə edə bilər. Təsirə məruz qalan sistemlərdə Fortinet-in təqdim etdiyi ən son təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Fortinet
FAQ2
What is the most effective mitigation against CVE-2025-68686?
It is recommended to apply the latest security updates provided by Fortinet on affected systems.
How can an attacker exploit CVE-2025-68686?
A remote unauthenticated attacker can gain unauthorized access to sensitive information via crafted HTTP requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.