What happened
A security weakness in FortiOS is being tracked as CVE-2025-25252. CVE-2025-25252 currently carries a MEDIUM 4 8 severity signal in the retained vulnerability data. CVE-2025-25252 puts affected FortiOS systems at risk when the vulnerable service or function is reachable from attacker-controlled network traffic.
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7 6 0 through 7 6 2, 7 4 0 through 7 4 6, 7 2 0 through 7 2 10, 7 0 0 through 7 0 16, 6 4 all versions may allow a remote attacker (e.
For organizations using FortiOS, the immediate question is whether CVE-2025-25252 is present in a deployment that handles untrusted input or supports a business-critical service.
Current sources do not report active exploitation of CVE-2025-25252; teams can use that window to identify affected FortiOS deployments, apply the vendor fix and confirm that the vulnerable path is no longer reachable.
Reference sources
Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.
Why leaders should care
Risk depends on whether FortiOS and the affected component are deployed and reachable. Exposure, privilege, business criticality and compensating controls should determine remediation priority.
What security teams should do now
- Inventory FortiOS deployments and confirm whether the affected component and vulnerable release are present.
- Apply the vendor patch or mitigation for CVE-2025-25252 and validate the affected path after remediation.
What is not yet confirmed
- So far, researchers have not reported exploitation, but that can change as vendor, government or threat-intelligence reporting develops.