CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It affects Fortinet. Exploitation may require the attacker to be authenticated.
CVE
CVE-2025-47855
Severity
CRITICAL
CVSS
9.8
EPSS
0.79%
Fortinet
Original NVD Description
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.