Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026011501013030 | Publication Time | 2026/01/15 13:34 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】A Critical Security Vulnerability Has Been Identified in Fortinet FortiFone Web Portal (CVE-2025-47855) |
|||
| [Content] Forwarded from TWCERTCC-200-202601-00000009 FortiFone Web Portal is the centralized management interface of the Fortinet FortiVoice system, used for remotely configuring phone extensions and monitoring call records and system performance. Recently, Fortinet released a critical security advisory indicating that this vulnerability (CVE-2025-47855, CVSS: 9.8) may allow unauthenticated attackers to obtain device configuration data through specially crafted HTTP or HTTPS requests, thereby gaining access to sensitive information. (Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
|
[Affected Platform] FortiFone versions 7.0.0 through 7.0.1 |
|||
|
[Recommended Actions] FortiFone version 3.0.24 or later FortiFone version 7.0.2 or later |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-169-10631-ea139-1.html |
|||