216.73.216.233

CVE-2025-61848

· Published 14/04/2026 16:16 · Modified 14/04/2026 16:16

Labels: CVE-2025-61848 2026-04-14CVE-2025-61848CWE-89[email protected]

Essential information

Published
14/04/2026 16:16
Modified
14/04/2026 16:16
Author
Creator
CVSS
7.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.8, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4.0 through 7.4.8, FortiManager Cloud 7.2 all versions, FortiManager Cloud 7.0 all versions may allow a privileged authenticated attacker to execute unauthorized code or commands via JSON RPC API

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fortinet / fortianalyzer cpe:2.3:a:fortinet:fortianalyzer:7.6.0-7.6.4:*:*:*:*:*:*:*
fortinet / fortianalyzer cpe:2.3:a:fortinet:fortianalyzer:7.4.0-7.4.8:*:*:*:*:*:*:*
fortinet / fortianalyzer cpe:2.3:a:fortinet:fortianalyzer:7.2:*:*:*:*:*:*:*
fortinet / fortianalyzer cpe:2.3:a:fortinet:fortianalyzer:7.0:*:*:*:*:*:*:*
fortinet / fortianalyzer cloud cpe:2.3:a:fortinet:fortianalyzer_cloud:7.6.0-7.6.4:*:*:*:*:*:*:*
fortinet / fortianalyzer cloud cpe:2.3:a:fortinet:fortianalyzer_cloud:7.4.0-7.4.8:*:*:*:*:*:*:*
fortinet / fortianalyzer cloud cpe:2.3:a:fortinet:fortianalyzer_cloud:7.2:*:*:*:*:*:*:*
fortinet / fortianalyzer cloud cpe:2.3:a:fortinet:fortianalyzer_cloud:7.0:*:*:*:*:*:*:*
fortinet / fortimanager cpe:2.3:a:fortinet:fortimanager:7.6.0-7.6.4:*:*:*:*:*:*:*
fortinet / fortimanager cpe:2.3:a:fortinet:fortimanager:7.4.0-7.4.8:*:*:*:*:*:*:*
fortinet / fortimanager cpe:2.3:a:fortinet:fortimanager:7.2:*:*:*:*:*:*:*
fortinet / fortimanager cpe:2.3:a:fortinet:fortimanager:7.0:*:*:*:*:*:*:*
fortinet / fortimanager cloud cpe:2.3:a:fortinet:fortimanager_cloud:7.6.0-7.6.4:*:*:*:*:*:*:*
fortinet / fortimanager cloud cpe:2.3:a:fortinet:fortimanager_cloud:7.4.0-7.4.8:*:*:*:*:*:*:*
fortinet / fortimanager cloud cpe:2.3:a:fortinet:fortimanager_cloud:7.2:*:*:*:*:*:*:*
fortinet / fortimanager cloud cpe:2.3:a:fortinet:fortimanager_cloud:7.0:*:*:*:*:*:*:*

References