VDB

CVE-2025-47855

CVE-2025-47855 PUBLISHED CVSS 9.300000190734863 CRITICAL

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.

EPSS 1.19% · 79.2th percentile

Risk Scores

CVSS v3.1
9.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:C
EPSS Score
1.19%
79.2th percentile

Affected Products

VendorProductVersions
FortinetFortiFone7.0.0, 3.0.13

Timeline

  • Jan 13, 2026 CVE Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 13, 2026 PoC Published
  • Jan 14, 2026 EPSS Score
  • Jan 14, 2026 CVE Updated
  • Jan 17, 2026 EPSS Score
  • Jan 18, 2026 PoC Published
  • Jan 20, 2026 EPSS Score
  • Jan 23, 2026 EPSS Score
  • Jan 26, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›