CVE-2025-58325
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenti
Severity
High 7.8
CVSS 3.1
Exploited
Not listed
EPSS
0.003
21.0th percentile
Discovered by
Not disclosed
Published
Oct 14, 2025
Assigned by fortinet
Description
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI commands.
Weakness: CWE-684
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiOS
Vendor remediation
Upgrade to FortiOS version 7.6.1 or above Upgrade to FortiOS version 7.4.6 or above Upgrade to FortiOS version 7.2.11 or above Upgrade to FortiOS version 7.0.16 or above