cbcvebase.
CVE-2025-25256
published 2025-08-12

CVE-2025-25256: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0…

PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
55.34%
98.9th percentile
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through 7.3.1, 7.2.0 through 7.2.5, 7.1.0 through 7.1.7, 7.0.0 through 7.0.3 and before 6.7.9 allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.

Affected

19 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortisiem
fortinetfortisiem
fortinetfortisiem>= 5.4.0 < 6.7.106.7.10
fortinetfortisiem6.1.0 – 6.1.2
fortinetfortisiem6.2.0 – 6.2.1
fortinetfortisiem6.3.0 – 6.3.3
fortinetfortisiem6.4.0 – 6.4.4
fortinetfortisiem6.5.0 – 6.5.3
fortinetfortisiem6.6.0 – 6.6.5
fortinetfortisiem6.7.0 – 6.7.9
fortinetfortisiem>= 7.0.0 < 7.0.47.0.4
fortinetfortisiem7.0.0 – 7.0.3
fortinetfortisiem>= 7.1.0 < 7.1.87.1.8
fortinetfortisiem7.1.0 – 7.1.7
fortinetfortisiem>= 7.2.0 < 7.2.67.2.6
fortinetfortisiem7.2.0 – 7.2.5
fortinetfortisiem>= 7.3.0 < 7.3.27.3.2
fortinetfortisiem7.3.0 – 7.3.1

Detection & IOCsextracted from sources · hover to see the quote

port7900
  • The exploitation entry point is the phMonitor service on TCP port 7900; restrict or monitor inbound connections to this port on FortiSIEM appliances.
  • Exploitation is delivered via crafted CLI requests to FortiSIEM; monitor for anomalous or unexpected CLI activity originating from unauthenticated sessions.
  • Fortinet confirmed functional exploit code exists in the wild; treat any unpatched FortiSIEM instance as actively at risk and prioritize patching.
  • ·Fortinet states that exploitation does not produce distinctive IOCs, making post-compromise detection unreliable; assume compromise if unpatched and exposed.
  • ·FortiSIEM versions 5.4 through 6.6 are vulnerable but end-of-life and will not receive a patch; migration to a supported release is required.
  • ·Restricting access to port 7900 is only a workaround and does not remediate the underlying vulnerability; patching is still required.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.