Vulnerability details
Advisory: SB20250812104 - OS Command Injection in FortiSIEM
Vulnerable component: FortiSIEM
CVE-ID: CVE-2025-25256
CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description:
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in an os command ('os command injection'). An unauthenticated attacker can execute unauthorized code or commands via crafted CLI requests.
Note, the vulnerability is being actively exploited in the wild.
External links: