Unauthenticated access to local configuration

Summary

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiFone Web Portal page may allow an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.

Version Affected Solution
FortiFone 7.2 Not affected Not Applicable
FortiFone 7.0 7.0.0 through 7.0.1 Upgrade to 7.0.2 or above
FortiFone 3.0 3.0.13 through 3.0.23 Upgrade to 3.0.24 or above

Acknowledgement

Internally discovered and reported by Théo Leleu from Fortinet Product Security team.

Timeline

2026-01-13: Initial publication