← Vulnerability feed

Vulnerability record · CVE-2025-25256 · published 12 August 2025

CVE-2025-25256: FortiSIEM unauthenticated OS command injection via crafted CLI requests

Fortinet · Fortisiem

FortiSIEM contains an OS command injection flaw (CWE-78) reachable through crafted CLI requests, affecting a very wide range of releases from 4.7 through 7.3.1. Because it is unauthenticated and network-reachable, it exposes the SIEM platform itself, a high-value target holding security telemetry and credentials.

9.8 CVSS 3.1 Critical EPSS 65% · top 0.8% CWE-78 · OS command injection
9.8CVSS 3.1 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
18 Aug 2026Last modified by NVD

Description

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0.0 through 7.0.3, FortiSIEM 6.7.0 through 6.7.9, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions, FortiSIEM 6.3 all versions, FortiSIEM 6.2 all versions, FortiSIEM 6.1 all versions, FortiSIEM 5.4 all versions, FortiSIEM 5.3 all versions, FortiSIEM 5.2 all versions, FortiSIEM 5.1 all versions, FortiSIEM 5.0 all versions, FortiSIEM 4.10 all versions, FortiSIEM 4.9 all versions, FortiSIEM 4.7 all versions allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable command injection with CVSS 9.8 and very high EPSS on a security-critical appliance.

What it is

FortiSIEM contains an OS command injection flaw (CWE-78) reachable through crafted CLI requests, affecting a very wide range of releases from 4.7 through 7.3.1. Because it is unauthenticated and network-reachable, it exposes the SIEM platform itself, a high-value target holding security telemetry and credentials.

Impact

An unauthenticated attacker can execute arbitrary code or commands on the FortiSIEM host, giving full control of the appliance and its data.

Attack surface

Reached over the network via crafted CLI requests with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not specify which interface or port is exposed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.628 (99th percentile) and public proof-of-concept material exists from watchTowr, indicating active research and likely exploitation interest.

What to do

  • Upgrade FortiSIEM to a fixed release per Fortinet advisory FG-IR-25-152; patch is the primary action.
  • Restrict network access to FortiSIEM management and CLI interfaces to trusted hosts only.
  • Isolate FortiSIEM from untrusted networks and segment it from general user traffic.
  • Monitor Fortinet advisory and vendor guidance for interim workarounds if immediate upgrade is not possible.
  • Audit appliance accounts and credentials for signs of tampering after exposure.

Detection

  • Alert on unexpected child processes spawned by FortiSIEM web or CLI service processes.
  • Monitor FortiSIEM logs for anomalous or malformed CLI requests and command execution events.
  • Watch for outbound connections from the FortiSIEM host to unknown external addresses.
  • Review host process telemetry for shell invocations (sh, bash) originating from application services.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-25256 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-64155FortiSIEM OS command injection via crafted TCP requestsFortiSIEM contains an OS command injection flaw (CWE-78) reachable through crafted TCP requests. Multiple 6.7.x through 7.4.0 branches are affected, …EPSS 43%analysed9.8CVE-2024-23109Fortinet fortisiem os command injection vulnerabilityAn improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute un…EPSS 3.2%9.8CVE-2024-23108FortiSIEM OS command injection via crafted API requestsFortiSIEM fails to neutralize special elements used in OS commands, allowing command injection through crafted API requests. With a CVSS 3.1 score of…EPSS 78%analysed9.8CVE-2023-36553Fortinet fortisiem os command injection vulnerabilityA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.…EPSS 1.9%9.8CVE-2023-34992FortiSIEM OS command injection via crafted API requestsFortiSIEM fails to neutralize special elements in OS commands, allowing command injection through crafted API requests. With a CVSS 3.1 score of 9.8 …EPSS 80%analysed9.8CVE-2023-26204Fortinet fortisiem insufficiently protected credentials vulnerabilityA plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 al…EPSS 0.43%9.8CVE-2019-16153Fortinet fortisiem hard-coded credentials vulnerabilityA hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device dat…EPSS 1.2%8.8CVE-2023-40714Fortinet fortisiem relative path traversal vulnerabilityA relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate pr…EPSS 0.61%

Source: NIST National Vulnerability Database (record CVE-2025-25256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.