CVE-2025-31149 · Fortinet
Fortinet FortiOS SSL VPN Bypass
- Severity:
- Medium
- CVSS:
- 6.2
- Published:
- May 8, 2025
Summary
An authentication logic flaw allows session reuse against the SSL VPN portal.
Affected products
FortiOS SSL VPN portals on affected firmware branches.
Impact
Unauthorised network access using a stale session artefact.
Recommended action
Upgrade firmware, rotate VPN sessions, and enforce multi-factor authentication.
Need clarity fast?
Whether you're a website owner, product team, or business leader, we'll expertly help you investigate, assess, and secure what matters most.
- 24/7 secure intake
- Confidential and discreet
- Rapid expert response
We respect your privacy. No spam. Ever. Or email support@techforensiq.com