{"id":3555,"date":"2025-05-15T10:25:30","date_gmt":"2025-05-15T10:25:30","guid":{"rendered":"https:\/\/certera.com\/blog\/?p=3555"},"modified":"2025-05-15T10:25:31","modified_gmt":"2025-05-15T10:25:31","slug":"tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise","status":"publish","type":"post","link":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/","title":{"rendered":"TACACS+ Authentication Bypass Flaw Exposes Devices to Full Compromise\u00a0"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Cybersecurity experts are concerned about a high-impact vulnerability in Fortinet&#8217;s FortiOS, FortiProxy, and FortiSwitchManager, designated as CVE-2025-22252. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerability could allow the attacker to circumvent authentication and gain privileges as an administrator on enterprise networks that deploy Fortinet security appliances.\u00a0\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-cve-2025-22252\">What is CVE-2025-22252?\u00a0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CVE-2025-22252 is an authentication for critical function vulnerability with a CVSSv3 score of 9.0 for Fortinet products FortiOS, FortiProxy, and FortiSwitchManager that are set up to use TACACS+ with ASCII authentication. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If it is exploited, an attacker with limited privileges can bypass authentication and obtain administrator privileges on the device.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-affected-products-and-versions\">Affected Products and Versions\u00a0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The critical vulnerability affects several Fortinet products that are set up to use TACACS+ with ASCII authentication. The vulnerability exists in FortiOS, FortiProxy, and FortiSwitchManager on identified firmware versions. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The affected versions are FortiOS versions 7.6.0\u00a0or 7.4.4 to 7.4.6, FortiProxy 7.6.0 and 7.6.1, and FortiSwitchManager 7.2.5. Any version older than FortiOS 7.2, 7.0, or 6.4, or any earlier build of FortiProxy or FortiSwitchManager, is not affected by this vulnerability. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations impacted by this vulnerability should take action immediately by upgrading or implementing temporary mitigation.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-official-fixes-and-recommendations\">Official Fixes and Recommendations\u00a0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Fortinet has rolled out firmware upgrades that fully address CVE-2025-22252. If you are using FortiOS, you should upgrade to v7.4.7 or v7.6.1 or higher. FortiProxy users should upgrade to at least v7.6.2. FortiSwitchManager users should upgrade to at least v7.2.6. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are unable to patch immediately, Fortinet offers a workaround: change the authentication method to PAP, MSCHAP, or CHAP (any of those because they do not suffer from the vulnerability). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This workaround can be completed through CLI configuration changes, and it was described as leveraging the benefit of the Fortinet products without the ability for anyone to access it as an administrator.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-is-this-vulnerability-so-dangerous\">Why is this vulnerability so Dangerous?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CVE-2025-22252 is a high-severity vulnerability because it provides a complete authentication bypass to sensitive operations in Fortinet appliances. If an attacker knows an existing administrator username, they can trick the system into providing administrative access \u2014 they don&#8217;t need the password either! <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a result, this flaw is incredibly dangerous in Enterprise environments, especially anywhere Fortinet firewalls, proxies, or switch managers are used to protect infrastructure. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attacker could fully exploit the experience of gaining full control over network security devices, exposing internal lateral movement through the system, exfiltrating concrete network data, and even disabling critical defenses with no significant traces (i.e., this is really bad news in terms of compromising infrastructure).\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cvss-scores-and-risk-assessment\">CVSS Scores and Risk Assessment\u00a0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here are the vulnerability ratings that define the severity of CVE-2025-22252, helping security teams prioritize action:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CVSS v3 Base Score: 9.8 (Critical)\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CVSS v3 Temporal Score: 8.5\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Vector: CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CVSS v2 Base Score: 10.0 (Critical)\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Temporal Score: 7.4\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Exploitability: No public exploits currently known\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Risk Factor: Critical (per Tenable and Fortinet assessment)\u00a0<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-security-teams-should-do-now\">What Security Teams Should Do Now?<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Audit your Fortinet deployments<\/strong> &#8211; In particular, check for versions indicated as affected.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Patch immediately<\/strong> \u2013 If you are running the vulnerable versions noted above.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Use a recommended workaround, whenever possible<\/strong> \u2013 Consider alternative TACACS+ authentication methods if you&#8217;re not able to apply the patches.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Monitor for unauthorized administrator logins<\/strong> \u2013 Set an alert for any suspicious logins.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Run external vulnerability scans<\/strong> &#8211; If a scanner shows other flaws not patched by Fortinet the flaw or exploit can be added to the threat chain of unique vulnerability, and can be exploited.\u00a0<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-stay-protected-with-sitelock\">Stay Protected with SiteLock<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Don&#8217;t let the attackers find the vulnerabilities in your network. Using <a href=\"https:\/\/certera.com\/services\/vulnerability-scanning-patching\">SiteLock&#8217;s Vulnerability Scanning<\/a> and Automated Patching solutions you can find, prioritize, and remediate existing security flaws similar to CVE-2025-22252 (and many others) before they are exploitable.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity experts are concerned about a high-impact vulnerability in Fortinet&#8217;s FortiOS, FortiProxy, and FortiSwitchManager, designated as CVE-2025-22252. The vulnerability could allow the attacker to circumvent authentication and gain privileges as an administrator on enterprise networks that deploy Fortinet security appliances.\u00a0\u00a0 What is CVE-2025-22252?\u00a0 CVE-2025-22252 is an authentication for critical function vulnerability with a CVSSv3 score<span class=\"morelink d-block mt-3\"><a href=\"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/\">Read More<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":3557,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[32],"tags":[685],"class_list":["post-3555","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-vulnerability","tag-cve-2025-22252-authentication-vulnerability","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Fortinet FortiGate TACACS+ Authentication Bypass - CVE-2025-22252<\/title>\n<meta name=\"description\" content=\"Multiple vulnerabilities have been discovered in Fortinet Products. A missing authentication for critical function vulnerability. Patch now!.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Fortinet FortiGate TACACS+ Authentication Bypass - CVE-2025-22252\" \/>\n<meta property=\"og:description\" content=\"Multiple vulnerabilities have been discovered in Fortinet Products. A missing authentication for critical function vulnerability. Patch now!.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/\" \/>\n<meta property=\"og:site_name\" content=\"EncryptedFence by Certera - Web &amp; Cyber Security Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/certeraLLC\/\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-15T10:25:30+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-15T10:25:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/05\/fortinet-vulnerability-alert.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"620\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Janki Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:site\" content=\"@certera_llc\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Janki Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/\"},\"author\":{\"name\":\"Janki Mehta\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\"},\"headline\":\"TACACS+ Authentication Bypass Flaw Exposes Devices to Full Compromise\u00a0\",\"datePublished\":\"2025-05-15T10:25:30+00:00\",\"dateModified\":\"2025-05-15T10:25:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/\"},\"wordCount\":623,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/fortinet-vulnerability-alert.webp\",\"keywords\":[\"CVE-2025-22252 Authentication Vulnerability\"],\"articleSection\":[\"Vulnerability\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/#respond\"]}],\"copyrightYear\":\"2025\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/\",\"name\":\"Fortinet FortiGate TACACS+ Authentication Bypass - CVE-2025-22252\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/fortinet-vulnerability-alert.webp\",\"datePublished\":\"2025-05-15T10:25:30+00:00\",\"dateModified\":\"2025-05-15T10:25:31+00:00\",\"description\":\"Multiple vulnerabilities have been discovered in Fortinet Products. A missing authentication for critical function vulnerability. Patch now!.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/#primaryimage\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/fortinet-vulnerability-alert.webp\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/fortinet-vulnerability-alert.webp\",\"width\":960,\"height\":620,\"caption\":\"CVE-2025-22252 Fortinet Security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/certera.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TACACS+ Authentication Bypass Flaw Exposes Devices to Full Compromise\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"name\":\"EncryptedFence by Certera - Web & Cyber Security Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\"},\"alternateName\":\"Certera's EncryptedFence Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/certera.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#organization\",\"name\":\"Certera\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"contentUrl\":\"https:\\\/\\\/certera.com\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-encryptedfence.svg\",\"caption\":\"Certera\"},\"image\":{\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/certeraLLC\\\/\",\"https:\\\/\\\/x.com\\\/certera_llc\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/certera-llc\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/certera.com\\\/blog\\\/#\\\/schema\\\/person\\\/e5a476aa90d9e02260ebfe4b0bf046b7\",\"name\":\"Janki Mehta\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g\",\"caption\":\"Janki Mehta\"},\"description\":\"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\\\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.\",\"sameAs\":[\"https:\\\/\\\/certerassl.com\\\/\"],\"url\":\"https:\\\/\\\/certera.com\\\/blog\\\/author\\\/certerabguser\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Fortinet FortiGate TACACS+ Authentication Bypass - CVE-2025-22252","description":"Multiple vulnerabilities have been discovered in Fortinet Products. A missing authentication for critical function vulnerability. Patch now!.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/","og_locale":"en_US","og_type":"article","og_title":"Fortinet FortiGate TACACS+ Authentication Bypass - CVE-2025-22252","og_description":"Multiple vulnerabilities have been discovered in Fortinet Products. A missing authentication for critical function vulnerability. Patch now!.","og_url":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/","og_site_name":"EncryptedFence by Certera - Web &amp; Cyber Security Blog","article_publisher":"https:\/\/www.facebook.com\/certeraLLC\/","article_published_time":"2025-05-15T10:25:30+00:00","article_modified_time":"2025-05-15T10:25:31+00:00","og_image":[{"width":960,"height":620,"url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/05\/fortinet-vulnerability-alert.webp","type":"image\/jpeg"}],"author":"Janki Mehta","twitter_card":"summary_large_image","twitter_creator":"@certera_llc","twitter_site":"@certera_llc","twitter_misc":{"Written by":"Janki Mehta","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/#article","isPartOf":{"@id":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/"},"author":{"name":"Janki Mehta","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7"},"headline":"TACACS+ Authentication Bypass Flaw Exposes Devices to Full Compromise\u00a0","datePublished":"2025-05-15T10:25:30+00:00","dateModified":"2025-05-15T10:25:31+00:00","mainEntityOfPage":{"@id":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/"},"wordCount":623,"commentCount":0,"publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"image":{"@id":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/05\/fortinet-vulnerability-alert.webp","keywords":["CVE-2025-22252 Authentication Vulnerability"],"articleSection":["Vulnerability"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/#respond"]}],"copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/certera.com\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/","url":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/","name":"Fortinet FortiGate TACACS+ Authentication Bypass - CVE-2025-22252","isPartOf":{"@id":"https:\/\/certera.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/#primaryimage"},"image":{"@id":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/#primaryimage"},"thumbnailUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/05\/fortinet-vulnerability-alert.webp","datePublished":"2025-05-15T10:25:30+00:00","dateModified":"2025-05-15T10:25:31+00:00","description":"Multiple vulnerabilities have been discovered in Fortinet Products. A missing authentication for critical function vulnerability. Patch now!.","breadcrumb":{"@id":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/#primaryimage","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/05\/fortinet-vulnerability-alert.webp","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2025\/05\/fortinet-vulnerability-alert.webp","width":960,"height":620,"caption":"CVE-2025-22252 Fortinet Security"},{"@type":"BreadcrumbList","@id":"https:\/\/certera.com\/blog\/tacacs-authentication-bypass-flaw-exposes-devices-to-full-compromise\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/certera.com\/blog\/"},{"@type":"ListItem","position":2,"name":"TACACS+ Authentication Bypass Flaw Exposes Devices to Full Compromise\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/certera.com\/blog\/#website","url":"https:\/\/certera.com\/blog\/","name":"EncryptedFence by Certera - Web & Cyber Security Blog","description":"","publisher":{"@id":"https:\/\/certera.com\/blog\/#organization"},"alternateName":"Certera's EncryptedFence Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/certera.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/certera.com\/blog\/#organization","name":"Certera","url":"https:\/\/certera.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","contentUrl":"https:\/\/certera.com\/blog\/wp-content\/uploads\/2023\/08\/logo-encryptedfence.svg","caption":"Certera"},"image":{"@id":"https:\/\/certera.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/certeraLLC\/","https:\/\/x.com\/certera_llc","https:\/\/www.linkedin.com\/company\/certera-llc\/"]},{"@type":"Person","@id":"https:\/\/certera.com\/blog\/#\/schema\/person\/e5a476aa90d9e02260ebfe4b0bf046b7","name":"Janki Mehta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1fba817ef81065f1393461fc3a0d85c40f2cc826919819ea4df4b12d76566e62?s=96&d=https%3A%2F%2Fcertera.com%2Fblog%2Fwp-content%2Fuploads%2F2023%2F02%2Fhttps-vs-sftp-jpg.webp&r=g","caption":"Janki Mehta"},"description":"Janki Mehta is a passionate Cyber-Security Enthusiast who keenly monitors the latest developments in the Web\/Cyber Security industry. She puts her knowledge into practice and helps web users by arming them with the necessary security measures to stay safe in the digital world.","sameAs":["https:\/\/certerassl.com\/"],"url":"https:\/\/certera.com\/blog\/author\/certerabguser\/"}]}},"_links":{"self":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/3555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/comments?post=3555"}],"version-history":[{"count":1,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/3555\/revisions"}],"predecessor-version":[{"id":3556,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/posts\/3555\/revisions\/3556"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media\/3557"}],"wp:attachment":[{"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/media?parent=3555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/categories?post=3555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/certera.com\/blog\/wp-json\/wp\/v2\/tags?post=3555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}