CVE-2025-25256
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through 7.3.1, 7.2.0 through 7.2.5, 7.1.0 through 7.1.7, 7.0.0 through 7.0.3 and before 6.7.9 allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
- EPSS probability
- 60.34%
- CWE
- CWE-78
- Published
- 2025-08-12
- Last modified
- 2026-08-18
Affected products
- Fortinet FortiSIEM
- Fortinet FortiSIEM
- Fortinet FortiSIEM
- Fortinet FortiSIEM
- Fortinet FortiSIEM
- Fortinet FortiSIEM
- Fortinet FortiSIEM
- Fortinet FortiSIEM
Weakness type
Related vulnerabilities
- CVE-2026-13745 — Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables
- CVE-2026-88282 — GV-LPCLPC2011/2211 - Stored FTP-Username Command Injection
- CVE-2026-88277 — GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command Injection
- CVE-2026-88276 — GV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command Injection
- CVE-2026-88275 — GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection
- CVE-2026-88274 — GV-LPC2011/LPC2211 - Wireless SSID Command Injection
- CVE-2026-88273 — GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command Injection
- CVE-2026-88272 — GV-LPC2011/LPC2211 - Stored Administrator-Username Command Injection