Extremely Critical Vulnerability In FortiSwitch GUI Allows Attacker To Modify Admin Passwords post, april 9, 2025 Fortinet has issued urgent security updates to address a critical vulnerability in FortiSwitch that could allow attackers to change passwords without authorization. The flaw, identified as CVE-2024-48887, has been assigned a CVSS score of 9.8 out of 10. According to Fortinet’s advisory, the vulnerability lies in the FortiSwitch GUI and could allow a remote, unauthenticated attacker to alter admin passwords via a specially crafted request. The issue is linked to an unverified password change vulnerability (CWE-620). (7) WARNING: Extremely Critical Vulnerability In FortiSwitch GUI Allows Attacker To Modify Admin Passwords | LinkedIn: Extremely Critical Vulnerability In FortiSwitch GUI Allows Attacker To Modify Admin Passwords vulnerability 2025