Fortinet FortiFone Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing unauthorized access to sensitive information has been identified in Fortinet FortiFone versions 7.0.0 through 7.0.1 and 3.0.13 through 3.0.23. This vulnerability allows an unauthenticated attacker to obtain the device configuration by sending crafted HTTP or HTTPS requests.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive device configuration information.

Remediation

Users can upgrade to Fortinet FortiFone version 7.0.2 or above, or version 3.0.24 or above, depending on their current version.

Added: Jan 13, 2026, 5:32 PM
Updated: Jan 13, 2026, 5:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
2.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.