← Back to browse · API

CVE-2024-48887

Severity
CRITICAL
CVSS
9.3
EPSS
0.14833
Risk score
42.39
CISA KEV
No
PoC
No
Published
2025-04-08
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-10266, GHSA-W84W-59G8-PMG9
Products
Fortinet:FortiSwitch 6.4.0 ≤6.4.14, Fortinet:FortiSwitch 7.0.0 ≤7.0.10, Fortinet:FortiSwitch 7.2.0 ≤7.2.8, Fortinet:FortiSwitch 7.4.0 ≤7.4.4, Fortinet:FortiSwitch 7.6.0
Sources
euvd EUVD-2025-10266

Description

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

References