Trusted Hosts Bypass via SSH Key Vulnerability Information Summary: An Improper Privilege Management vulnerability [CWE-269] allows an authenticated administrator to bypass the trusted host policy via crafted CLI command. IR Number: FG-IR-25-545 Published Date: Nov 18, 2025 Component: CLI Severity: Low CVSSv3 Score: 1.8 Impact: Escalation of privilege CVE ID: CVE-2025-54821 Downloads: CVRF CSAF Affected Versions and Solutions Follow Recommended Upgrade Path Use the tool at: https://docs.fortinet.com/upgrade-tool Acknowledgement Nathan Jones from Orange Cyberdefense UK reported this vulnerability under responsible disclosure. Timeline 2025-11-18: Initial publication