CVE Vulnerabilities

CVE-2025-54660

Active Debug Code

Published: Nov 18, 2025 | Modified: Nov 20, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user password

Weakness

The product is released with debugging code still enabled or active.

Affected Software

Name Vendor Start Version End Version
Forticlient Fortinet 7.0.0 (including) 7.2.11 (excluding)
Forticlient Fortinet 7.4.0 (including) 7.4.4 (excluding)

Potential Mitigations

References