imPC@ndo IT

Tracker / CVE-2026-25690

CVE-2026-25690

Medium 4.3

An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through 5.2.1, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests.

Affected products and versions

fortinet fortideceptor
fortinet fortideceptor · 5.0.0 → 5.1.0
fortinet fortideceptor · 5.3.0 → 5.3.3
fortinet fortideceptor · 6.0.0 → 6.0.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References