Vulnerability record · CVE-2025-25256 · published 12 August 2025
CVE-2025-25256: FortiSIEM unauthenticated OS command injection via crafted CLI requests
Fortinet · Fortisiem
FortiSIEM contains an OS command injection flaw (CWE-78) reachable through crafted CLI requests, affecting a very wide range of releases from 4.7 through 7.3.1. Because it is unauthenticated and network-reachable, it exposes the SIEM platform itself, a high-value target holding security telemetry and credentials.
Description
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0.0 through 7.0.3, FortiSIEM 6.7.0 through 6.7.9, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions, FortiSIEM 6.3 all versions, FortiSIEM 6.2 all versions, FortiSIEM 6.1 all versions, FortiSIEM 5.4 all versions, FortiSIEM 5.3 all versions, FortiSIEM 5.2 all versions, FortiSIEM 5.1 all versions, FortiSIEM 5.0 all versions, FortiSIEM 4.10 all versions, FortiSIEM 4.9 all versions, FortiSIEM 4.7 all versions allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable command injection with CVSS 9.8 and very high EPSS on a security-critical appliance.
What it is
FortiSIEM contains an OS command injection flaw (CWE-78) reachable through crafted CLI requests, affecting a very wide range of releases from 4.7 through 7.3.1. Because it is unauthenticated and network-reachable, it exposes the SIEM platform itself, a high-value target holding security telemetry and credentials.
Impact
An unauthenticated attacker can execute arbitrary code or commands on the FortiSIEM host, giving full control of the appliance and its data.
Attack surface
Reached over the network via crafted CLI requests with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not specify which interface or port is exposed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.628 (99th percentile) and public proof-of-concept material exists from watchTowr, indicating active research and likely exploitation interest.
What to do
- Upgrade FortiSIEM to a fixed release per Fortinet advisory FG-IR-25-152; patch is the primary action.
- Restrict network access to FortiSIEM management and CLI interfaces to trusted hosts only.
- Isolate FortiSIEM from untrusted networks and segment it from general user traffic.
- Monitor Fortinet advisory and vendor guidance for interim workarounds if immediate upgrade is not possible.
- Audit appliance accounts and credentials for signs of tampering after exposure.
Detection
- Alert on unexpected child processes spawned by FortiSIEM web or CLI service processes.
- Monitor FortiSIEM logs for anomalous or malformed CLI requests and command execution events.
- Watch for outbound connections from the FortiSIEM host to unknown external addresses.
- Review host process telemetry for shell invocations (sh, bash) originating from application services.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-25256 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-25256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.