Technical Tip: Resolving CVE-2025-54821 Vulnerability in FortiOS version 7.4
Description
This article describes how to address the CVE-2025-54821 vulnerability in FortiOS. This vulnerability may allow an authenticated administrator to bypass trusted-host restrictions via specific CLI commands.
Scope
FortiGate version 7.4.
Solution
CVE-2025-54821 (FG-IR-25-545) – Trusted hosts bypass via SSH.
Severity: Low.
Reference: PSIRT FG-IR-25-545.
Details:
An Improper Privilege Management vulnerability (CWE-269) in FortiOS, FortiProxy, and FortiPAM may allow an authenticated administrator to bypass trusted-host policies via specially crafted CLI commands.
Resolution steps:
To remediate this vulnerability, perform the following:
Upgrade the firmware to a fixed version:
FortiOS v7.4.12.
FortiOS v7.6.4 or later.
Follow the recommended upgrade path using the Fortinet Upgrade Tool:
Verify the fix: Confirm that Bug ID 1179021 is included in the release notes of the upgraded version.
Verification:
The fix is confirmed in FortiOS v7.6.4 Release Notes, where the vulnerability is explicitly addressed:
Bug ID: 1179021.
FortiOS v7.6.4 is no longer vulnerable to CVE-2025-54821.
Reference:
Notes:
As of now, the FortiOS v7.4.12 release notes may not explicitly list this CVE, even though the fix is included in that version.
It is recommended to proceed with the upgrade to a supported version to ensure protection.
