CVE-2025-31149 · Fortinet

Fortinet FortiOS SSL VPN Bypass

Severity:
Medium
CVSS:
6.2
Published:
May 8, 2025

Summary

An authentication logic flaw allows session reuse against the SSL VPN portal.

Affected products

FortiOS SSL VPN portals on affected firmware branches.

Impact

Unauthorised network access using a stale session artefact.

Recommended action

Upgrade firmware, rotate VPN sessions, and enforce multi-factor authentication.

Back to vulnerability database

Need clarity fast?

Whether you're a website owner, product team, or business leader, we'll expertly help you investigate, assess, and secure what matters most.

  • 24/7 secure intake
  • Confidential and discreet
  • Rapid expert response

We respect your privacy. No spam. Ever. Or email support@techforensiq.com