← Vulnerability feed

Vulnerability record · CVE-2025-22859 · published 13 May 2025

CVE-2025-22859: Fortinet forticlientems relative path traversal vulnerability

Fortinet · Forticlientems

A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.

5.3 CVSS 3.1 Medium EPSS 0.58% · top 54.6% CWE-23 · Relative path traversal
5.3CVSS 3.1 base score
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-22859 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-35616FortiClientEMS improper access control allows unauthenticated code executionFortinet FortiClientEMS 7.4.5 through 7.4.6 contains an improper access control flaw (CWE-284) that lets an unauthenticated attacker send crafted req…KEVEPSS 9.1%analysed9.8CVE-2026-21643FortiClientEMS SQL injection allows unauthenticated remote code executionFortiClientEMS 7.4.4 fails to neutralize special elements in SQL commands, exposing a SQL injection reachable through crafted HTTP requests. Because …KEVEPSS 94%analysed9.8CVE-2026-59836Fortinet forticlientems improper certificate validation vulnerabilityA improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.…EPSS 0.22%9.8CVE-2024-23106Fortinet forticlientems improper restriction of authentication attempts vulnerabilityAn improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unau…EPSS 0.96%7.2CVE-2025-59922Fortinet forticlientems sql injection vulnerabilityAn improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientE…EPSS 7.8%6.7CVE-2026-39809Fortinet forticlientems sql injection vulnerabilityA improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, …EPSS 0.20%6.1CVE-2019-16149Fortinet forticlientems cross-site scripting vulnerabilityAn Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized co…EPSS 0.28%5.5CVE-2026-39810Fortinet forticlientems vulnerabilityA use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via d…EPSS 0.15%

Source: NIST National Vulnerability Database (record CVE-2025-22859), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.