CVE-2025-58325
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenti
Severity
High 7.8
CVSS 3.1
Exploited
Not listed
EPSS
0.003
21.5th percentile
Discovered by
Vendor
Vendor advisory field
Published
Oct 14, 2025
Assigned by fortinet
Description
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI commands.
Weakness: CWE-684
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiOS
Credit
Internally discovered and reported by Francois Ropert of Fortinet PSIRT team.
Vendor remediation
Upgrade to FortiOS version 7.6.1 or above Upgrade to FortiOS version 7.4.6 or above Upgrade to FortiOS version 7.2.11 or above Upgrade to FortiOS version 7.0.16 or above