---
title: "Critical Vulnerability in Fortinet Products: Authentication Bypass Risk"
description: A critical security vulnerability, CVE-2025-22252, has been identified in several Fortinet products, including FortiOS, FortiProxy, and FortiSwitchManager.
---

[Skip to content](https://1898advisories.burnsmcd.com/critical-vulnerability-in-fortinet-products-authentication-bypass-risk#main-content)

![1898-logo-grey-R-1](https://1898advisories.burnsmcd.com/hs-fs/hubfs/1898-logo-grey-R-1.webp?width=188&height=100&name=1898-logo-grey-R-1.webp)

- [Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)
- [Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)
- [View All](https://1898advisories.burnsmcd.com/)

Open main navigation

Close main navigation

- [Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)
- [Threat Hunt](https://1898advisories.burnsmcd.com/tag/threat-hunt)
- [View All](https://1898advisories.burnsmcd.com/)
- [Contact us](https://1898andco.burnsmcd.com/contact-us)

[Contact us](https://1898andco.burnsmcd.com/contact-us)

 May 15, 2025

# Critical Vulnerability in Fortinet Products: Authentication Bypass Risk

![Picture of The 1898 & Co. Team](https://1898advisories.burnsmcd.com/hs-fs/hubfs/1898%20Cyberthreat%20Advisory%20Blog%20Assets/1898-Co-Ampersand.png?width=50&name=1898-Co-Ampersand.png) [The 1898 & Co. Team](https://1898advisories.burnsmcd.com/author/1898-co-team)

A critical security vulnerability, CVE-2025-22252, has been identified in several Fortinet products, including FortiOS, FortiProxy, and FortiSwitchManager. This flaw allows attackers to bypass authentication and gain administrative access to systems configured with TACACS+ using ASCII authentication. The vulnerability poses a significant risk as it enables unauthorized users to potentially control network infrastructure devices, leading to data theft, network penetration, or service disruption. Fortinet has released patches for affected versions and recommends immediate updates.

In addition to the authentication bypass vulnerability, Fortinet has addressed a zero-day vulnerability in FortiVoice that was being exploited in the wild to execute arbitrary code. This highlights the ongoing threat landscape where attackers actively seek and exploit vulnerabilities in widely used products. Organizations using Fortinet products are urged to review their configurations and apply necessary patches to mitigate these risks.

The cybersecurity landscape continues to evolve with the integration of advanced technologies such as Defensive AI for endpoint security. These technologies claim high accuracy in threat detection and prevention, offering new avenues for organizations to bolster their defenses against emerging threats. A free seminar is available for those interested in learning more about leveraging AI for enhanced security measures.

#### Threats and Vulnerabilities

The primary threat discussed is the CVE-2025-22252 vulnerability affecting Fortinet products. This flaw allows attackers to bypass authentication on systems using TACACS+ with ASCII authentication, granting them administrative access. The potential impact includes unauthorized control over network devices, leading to data breaches, network penetration, and service disruptions. The vulnerability affects specific versions of FortiOS, FortiProxy, and FortiSwitchManager, with patches available for mitigation.

Another significant threat is the zero-day vulnerability in FortiVoice, which was actively exploited to execute arbitrary code. This vulnerability underscores the importance of timely patching and monitoring for indicators of compromise (IoCs) to prevent exploitation. Organizations using Fortinet products should remain vigilant and apply security updates promptly.

#### Client Impact

Clients using affected Fortinet products may face operational disruptions due to unauthorized access and control over network infrastructure. This could result in data breaches, financial losses, and damage to reputation. The authentication bypass vulnerability specifically threatens the integrity of network security by allowing attackers to impersonate legitimate administrators.

From a compliance perspective, failure to address these vulnerabilities could lead to regulatory challenges and potential penalties. Organizations must ensure their security measures align with relevant laws and standards to avoid audits or fines. It is crucial for clients to assess their current configurations and implement necessary updates or workarounds to maintain compliance and protect their assets.

#### Mitigations

To mitigate the identified risks, clients should consider the following actions:

1. Upgrade affected Fortinet products to the patched versions: FortiOS 7.6.1 or above, FortiOS 7.4.7 or above, FortiProxy 7.6.2 or above, and FortiSwitchManager 7.2.6 or above.
2. For those unable to update immediately, switch from ASCII authentication to alternative methods such as PAP, MSCHAP, or CHAP.
3. Regularly review and update network configurations to ensure they align with security best practices.
4. Monitor systems for indicators of compromise related to the FortiVoice zero-day vulnerability.
5. Attend seminars or training sessions on leveraging AI for endpoint security to enhance threat detection capabilities.

Implementing these measures will help reduce the risk of unauthorized access and maintain the integrity of network infrastructure. Clients are encouraged to stay informed about emerging threats and continuously evaluate their security posture.

#### 1898 & Co. Response

1898 & Co. is actively addressing the current threat landscape by offering tailored security solutions designed to mitigate risks associated with vulnerabilities like those found in Fortinet products. Our services include comprehensive vulnerability assessments, patch management strategies, and configuration reviews to ensure clients' systems are secure against known threats.

We are enhancing our security protocols by integrating advanced threat intelligence and AI-driven technologies into our offerings. This approach allows us to provide clients with cutting-edge solutions that improve threat detection accuracy and response times.

Our collaboration with industry partners and participation in cybersecurity research initiatives enable us to stay ahead of emerging threats and share valuable insights with our clients. We are committed to supporting organizations in navigating complex security challenges through proactive measures and expert guidance.

#### Sources

1. [Fortinet Security Advisory on CVE-2025-22252](https://www.fortiguard.com/psirt/FG-IR-24-472)
2. [CVE Details for CVE-2025-22252](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-22252)

[Cyberthreat](https://1898advisories.burnsmcd.com/tag/cyberthreat)

*The information in this cybersecurity advisory is provided "as is" for informational purposes only. 1898 & Co. does not provide any warranties or guarantees of any kind regarding this information. You assume all risks if you choose to rely on this information. In no event shall 1898 & Co. or its contractors or subcontractors be liable for any damages including, but not limited to, direct, indirect, special or consequential damages, arising out of, resulting from, or in any way connected with, this information, whether or not based upon warranty, contract, tort, or otherwise, whether or not arising out of negligence, and whether or not injury was sustained from, or arose out of the results of, or reliance upon the information*

*1898 & Co. does not endorse any product or service, except as expressly stated otherwise. Any reference to products or processes does not constitute or imply 1898 & Co.’s endorsement or recommendation.*

Subscribe

✕ Close

 

[Accessibility](https://1898andco.burnsmcd.com/accessibility)  |  [Privacy Statement](https://1898andco.burnsmcd.com/privacy)

© 2026 1898 & Co., a part of Burns & McDonnell. All Rights Reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "The 1898 & Co. Team",
    "url" : "https://1898advisories.burnsmcd.com/author/1898-co-team"
  },
  "dateModified" : "2026-04-30T21:02:07.109Z",
  "datePublished" : "2025-05-15T20:44:59.000Z",
  "headline" : "Critical Vulnerability in Fortinet Products: Authentication Bypass Risk",
  "mainEntityOfPage" : {
    "@id" : "https://1898advisories.burnsmcd.com/critical-vulnerability-in-fortinet-products-authentication-bypass-risk",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "//cdn2.hubspot.net/hub/477837/file-2585615236-jpg/Logo_1_Primary_2Color1.jpg"
    },
    "name" : "Burns & McDonnell Engineering Co"
  }
}
```