CVE-2025-25256
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through 7.3.1, 7.2.0 through 7.2.5, 7.1.0 throu
Description
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through 7.3.1, 7.2.0 through 7.2.5, 7.1.0 through 7.1.7, 7.0.0 through 7.0.3 and before 6.7.9 allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.
Weakness: CWE-78
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSIEM | SIEM & Log Management | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiSIEM
Vendor remediation
Please upgrade to FortiSIEM version 7.4.0 or above Please upgrade to FortiSIEM version 7.3.2 or above Please upgrade to FortiSIEM version 7.2.6 or above Please upgrade to FortiSIEM version 7.1.8 or above Please upgrade to FortiSIEM version 7.0.4 or above Please upgrade to FortiSIEM version 6.7.10 or above
References
- https://fortiguard.fortinet.com/psirt/FG-IR-25-152
- https://github.com/watchtowrlabs/watchTowr-vs-FortiSIEM-CVE-2025-25256
- https://labs.watchtowr.com/should-security-solutions-be-secure-maybe-were-all-wrong-fortinet-fortisiem-pre-auth-command-injection-cve-2025-25256/
- https://www.theregister.com/2025/08/13/fortinet_discloses_critical_bug/