CVE-2025-62631: 
FortiOS vulnerability analysis and mitigation

Overview

CVE-2025-62631 is an Insufficient Session Expiration vulnerability (CWE-613) in Fortinet FortiOS affecting the SSL VPN component. It allows an attacker to maintain unauthorized access to network resources via an active SSLVPN session that is not properly terminated after a user's password change, under specific conditions outside the attacker's control. Affected versions include FortiOS 6.4 (all versions), 7.0 (all versions), 7.2 (all versions), and 7.4.0; FortiOS 7.6 is not affected. The vulnerability was publicly disclosed on December 9, 2025, with a CVSS v3.1 base score of 5.3–5.6 (Medium) (FortiGuard Advisory).

Technical details

The root cause is classified as CWE-613 (Insufficient Session Expiration): when a user changes their password, the FortiOS SSLVPN component fails to invalidate existing active sessions under certain conditions. This means a previously authenticated session token remains valid and usable even after the credential change that should have revoked it. The attack vector is network-based, requires no privileges or user interaction, but has high attack complexity due to the dependency on specific conditions outside the attacker's control. No public proof-of-concept or technical write-up detailing the exact triggering conditions has been published (FortiGuard Advisory).

Impact

Successful exploitation allows an attacker who has previously obtained valid SSLVPN session credentials to maintain persistent access to protected network resources even after the legitimate user resets their password — a control typically relied upon to revoke unauthorized access. This undermines a key incident response action (password reset) and could allow continued lateral movement, data exfiltration, or persistence within the network. The confidentiality, integrity, and availability impacts are each rated Low, reflecting limited but real unauthorized access potential (FortiGuard Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of disclosure. Fortinet's advisory explicitly states "Known Exploited: No" (FortiGuard Advisory). The EPSS score is approximately 0.041%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity requirement — dependent on specific conditions outside the attacker's control — further limits practical exploitability.

Exploitation steps

  1. Obtain valid SSLVPN credentials: The attacker must first acquire valid credentials for a FortiOS SSLVPN account on an affected version (6.4.x, 7.0.x, 7.2.x, or 7.4.0), through phishing, credential stuffing, or other means.
  2. Establish an active SSLVPN session: Authenticate to the target FortiOS SSLVPN portal and establish an active session, capturing the session token or maintaining the VPN tunnel.
  3. Wait for password change event: The vulnerability is triggered when the legitimate user (or an administrator) changes the account password — a common incident response action after detecting unauthorized access.
  4. Maintain persistent access: Under the specific vulnerable conditions, the attacker's existing SSLVPN session is not terminated by the password change, allowing continued access to internal network resources through the still-valid session (FortiGuard Advisory).

Indicators of compromise

  • Network: Active SSLVPN tunnel connections from unexpected or previously unseen source IP addresses, particularly those persisting after a known password change event.
  • Logs: FortiOS VPN logs showing an authenticated session remaining active for a user account after a password change timestamp; look for session entries with authentication timestamps predating a recent credential update.
  • Logs: Concurrent SSLVPN sessions for the same user account from different source IPs, which may indicate a hijacked session running in parallel with a legitimate one.
  • Process/Behavior: Network traffic originating from the SSLVPN IP pool to internal resources after an account password reset, especially if the legitimate user is not actively connected.

Mitigation and workarounds

Fortinet has released a fix in FortiOS 7.4.1; users on FortiOS 7.4.0 should upgrade to 7.4.1 or above. Users on FortiOS 6.4 (all versions), 7.0 (all versions), and 7.2 (all versions) must migrate to a fixed release, as no in-branch patch is available for those branches. Fortinet recommends using the official upgrade path tool at https://docs.fortinet.com/upgrade-tool. As interim mitigations, administrators should implement strict session management, regularly review and manually terminate inactive or suspicious VPN sessions, and consider enforcing multi-factor authentication on SSLVPN to reduce the risk of credential-based session hijacking (FortiGuard Advisory).

Community reactions

The vulnerability was reported to Fortinet by Elmaddin Salahov from Caspisec under responsible disclosure, and Fortinet acknowledged the researcher in its advisory (FortiGuard Advisory). The disclosure generated routine tracking activity across vulnerability aggregators (Vulners, VulDB, CVEFeed) and security monitoring platforms (Tenable Nessus plugin 277943), but no significant public researcher commentary or media coverage has been identified, consistent with the Medium severity rating and lack of active exploitation.

Additional resources


Source: This report was generated using AI

Related FortiOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84393HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesSep 08, 2026
CVE-2026-71407HIGH8.1
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoYesAug 12, 2026
CVE-2026-71408MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoYesAug 12, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NoYesAug 12, 2026
CVE-2026-84392LOW2.7
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management