CVE-2025-25252

Executive Summary

FortiOS SSL VPN versions 7.6.0‑7.6.2, 7.4.0‑7.4.6, 7.2.0‑7.2.10, 7.0.0‑7.0.16, and 6.4 all allow a remote attacker who has a valid SAML record from a terminated session to re‑establish that session. The flaw stems from insufficient session expiration handling (CWE‑613). An attacker could regain access to the VPN without re‑authenticating, potentially compromising network resources. No CISA KEV listing yet.


Authoritative CVE Metadata - CVSS Base Score: 4.8 (MEDIUM) - Published: 2025-10-14T16:15:36.683 - Last Modified: 2026-09-13T04:17:02.730

Original Description: An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML record.

"Fear not for the future, weep not for the past."

— Percy Shelley
Source: NVD