CVE-2026-25690
medium
CVSS v3
6.5
CVSS v2
—
VIR risk
6.5
Description
An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through 5.2.1, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@fortinet.com — https://fortiguard.fortinet.com/psirt/FG-IR-26-138
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| fortinet | fortideceptor | {"startIncluding":"5.0.0","endIncluding":"5.1.0"} | |
| fortinet | fortideceptor | 5.2.0 | |
| fortinet | fortideceptor | 5.2.1 | |
References
CWEs
CWE-88
Verify integrity in audit chain (admin only). AS-IS.