CVE-2025-59718
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, Fo...
Affects 3 products across 2 vendors.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical vulnerability in Fortinet FortiOS and related products allows unauthenticated attackers to bypass FortiCloud SSO login authentication by crafting a SAML response message. This could lead to unauthorized access and compromise of the network, posing significant risks to operational technology environments.
BSID: BS-2025-GLOBAL-270552-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-59718?
What is the CVSS score for CVE-2025-59718?
Is CVE-2025-59718 actively exploited?
How do I remediate CVE-2025-59718?
What systems are affected by CVE-2025-59718?
What NERC-CIP standard applies to CVE-2025-59718?
What IEC 62443 requirement maps to CVE-2025-59718?
| CVE ID | CVE-2025-59718 |
|---|---|
| BSID | BS-2025-GLOBAL-270552-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2025-12-09 |
| Last Modified | 2026-06-17 |
| ICS Relevance | 85% |
| Weakness (CWE) | |
| Verticals | |
| Domains | |
| Source | NVD |
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from improper verification of cryptographic signatures in the SAML response messages. An unauthenticated attacker can craft a malicious SAML response to bypass the FortiCloud SSO login mechanism, gaining unauthorized access to the affected systems. This can lead to full control over the network, potentially allowing further attacks on connected OT devices.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Affected Versions |
|---|---|---|
| Fortinet | Fortios | ≥ 7.0.0, ≤ 7.0.17 ≥ 7.2.0, ≤ 7.2.11 ≥ 7.4.0, ≤ 7.4.8 ≥ 7.6.0, ≤ 7.6.3 |
| Fortinet | Fortiproxy | ≥ 7.0.0, ≤ 7.0.21 ≥ 7.2.0, ≤ 7.2.14 ≥ 7.4.0, ≤ 7.4.10 ≥ 7.6.0, ≤ 7.6.3 |
| Fortinet | Fortiswitchmanager | ≥ 7.0.0, ≤ 7.0.5 ≥ 7.2.0, ≤ 7.2.6 |
| Siemens | — | — |
| Siemens | Ruggedcom Ape1808 Firmware | All versions |
| CISA known-exploited | ● Active Exploitation Confirmed (added 2025-12-16) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict SAML response validation and monitoring for anomalous authentication attempts. Ensure that all SAML responses are verified against a trusted certificate authority and that any deviations are immediately flagged and investigated.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. A network rule is only drafted when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 as it allows unauthorized access to the network, which can compromise the security of electronic security perimeters and control systems.
This CVE maps to SR 7.6 because it involves a failure in the authentication and authorization mechanisms, which can lead to unauthorized access and control of the system, violating the security requirements for access control.
Drafted by AI and not validated for your network. Test in an isolated environment before any production deployment. Compensating control only - does not replace vendor patch.
AI Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 01e0e127282958a023c006a80909e9d0f7b1e7f99e6c49d3175fc0a4fe8693fc94cd9958efe3bbe3da1cfb8721f80ab2ca1bab4157c2b76daa4f4393b66dfd8b |
This Vulnerability Is Being Actively Exploited
CVE-2025-59718 is on the CISA known-exploited list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.
Create a free account →