Fortinet has issued an urgent advisory disclosing a critical vulnerability in its FortiPAM and FortiSwitch Manager, which could allow attackers to completely bypass the verification process through brute-force methods.
See also: Coordinated attack on Cisco, Fortinet and Palo Alto Networks devices

The vulnerability, tracked as CVE-2025-49201, stems from a weak authentication mechanism in the Web Application Delivery (WAD) and Graphical User Interface (GUI), and has been classified as CWE-1390.
With a CVSS v3.1 score of 7.4, which is classified as high severity, the vulnerability poses risks of unauthorized code execution or command injection, potentially giving remote attackers complete control over affected systems.
The issue affects multiple versions of FortiPAM, Fortinet's privileged access management solution, as well as select versions of FortiSwitch Manager, which manages network switch configurations.
Specifically, FortiPAM versions 1.5.0, 1.4.0 through 1.4.2, and all versions of 1.3, 1.2, 1.1, and 1.0 are vulnerable. For FortiSwitch Manager, versions 7.2.0 through 7.2.4 in the 7.2 series are affected, while the 7.0 series remains unaffected.
See also: WatchGuard fixes critical VPN flaw in firewalls

Attackers need network access and could exploit this vulnerability with persistent brute-force attempts, although no public exploits have yet appeared.
Fortinet urges immediate patching to address the threats. Users of the vulnerable FortiPAM 1.5 should upgrade to version 1.5.1 or later, while those using version 1.4 need version 1.4.3 or later. For older branches such as 1.3 and below, it is necessary to migrate to a patched version.
FortiSwitch Manager 7.2 users should update to version 7.2.5 or higher . The company emphasizes the need to monitor for unusual login attempts and implement multi-factor authentication as interim defense measures.
The vulnerability was discovered internally by Gwendal Guégniaud of Fortinet's Product Security team and published on October 14, 2025, under the internal report FG-IR-25-010.
See also: New Fortinet FortiWeb breaches linked to public RCE exploits

This revelation comes amid growing concerns about supply chain attacks targeting network management tools, highlighting the need for immediate updates in business environments.
