CVE-2025-58692
published 2025-11-18CVE-2025-58692: An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7.2.0…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.29%
20.9th percentile
An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortivoice | — | — |
| fortinet | fortivoice | >= 7.0.0 < 7.0.8 | 7.0.8 |
| fortinet | fortivoice | >= 7.2.0 < 7.2.3 | 7.2.3 |
| fortinet | fortivoice | 7.2.0 – 7.2.2 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for authenticated HTTP/HTTPS requests to FortiVoice endpoints containing SQL injection payloads (e.g., unexpected SQL metacharacters or stacked queries in request parameters) ↗
- →Scope detection to FortiVoice versions 7.2.0–7.2.2 and 7.0.0–7.0.7; traffic from patched versions outside these ranges can be deprioritized ↗
- ·Exploitation requires prior authentication; unauthenticated access alone is insufficient to trigger the SQL injection vulnerability ↗
- ·The vulnerability is present across two distinct version branches (7.0.x and 7.2.x); ensure detection and patching coverage spans both branches ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerabi...
vendor_fortinet·2025-11-18·CVSS 8.8
CVE-2025-58692 [HIGH] CWE-89 An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerabi...
FG-IR-25-666: An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerabi...
An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.
CVEs: CVE-2025-58692
CWEs: CWE-89
CVSS: 8.8 (high)
Affected products: FortiVoice, Fortinet
GHSA
GHSA-9fcw-vm3q-wfjq: An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] in Fortinet FortiVoice 7
ghsa_unreviewed·2025-11-18
CVE-2025-58692 [HIGH] CWE-89 GHSA-9fcw-vm3q-wfjq: An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] in Fortinet FortiVoice 7
An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-18
Published