Two databases score the same flaw 7.4 and 9.8. Your patch queue is sorted wrong.
Fortinet scores CVE-2025-25249 at 7.4 and calls it high; NVD scores the same bug 9.8 and calls it critical — and it is the one with a documented mass campaign behind it. CISA's own federal directive stopped sorting by severity in June. Here is the four-route, four-tag, one-afternoon review that copies its schema without pretending it applies to you.




