Zero-day vulnerability in FortiSIEM

OS Command Injection
CVE-2025-25256

Vulnerability details

Advisory: SB20250812104 - OS Command Injection in FortiSIEM

Vulnerable component: FortiSIEM

CVE-ID: CVE-2025-25256

CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Description:

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements used in an os command ('os command injection'). An unauthenticated attacker can execute unauthorized code or commands via crafted CLI requests.

Note, the vulnerability is being actively exploited in the wild.