Critical FortiSIEM flaw under active exploitation, Fortinet warns
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-25256 | Unauthenticated OS command injection in Fortinet FortiSIEM (CVE-2025-25256) CVE-2025-25256 is a critical (CVSS 9.8) OS command injection flaw (CWE-78) in Fortinet's FortiSIEM SIEM platform. An unauthenticated attacker can trigger it by sending specially crafted CLI requests over the network, which the appliance fails to properly neutralize before execution. Successful exploitation allows the attacker to execute unauthorized code or commands on the affected system without credentials or user interaction, effectively giving control of the appliance. Essentially every currently supported and many older FortiSIEM releases are affected, spanning versions 4.7 through 7.3.1. Fortinet has confirmed exploit code is being used in the wild, and the flaw carries a high 60.3% EPSS probability of exploitation within 30 days, though it is not yet in CISA's KEV catalog. Do: Upgrade FortiSIEM to a fixed release per Fortinet's security advisory, ensuring the deployed version falls outside all affected ranges listed above; given in-the-wild exploitation and a ~60% EPSS probability, prioritize externally reachable instances. Until patched, restrict network access to the appliance's CLI/management-facing services and review logs for unexpected commands or connections that may indicate compromise. | 9.8 | 60% |
| largetens of thousands of deployed FortiSIEM instances worldwide (order-of-magnitude estimate) |
Full article232 words · extracted from securityaffairs.com · click to collapse

Fortinet warns of a critical FortiSIEM vulnerability, tracked as CVE-2025-25256, that is actively exploited in attacks in the wild.
Fortinet warns customers of a critical vulnerability, tracked as CVE-2025-25256 (CVSS score of 9.8), affecting FortiSIEM for which an exploit exists in the wild.
Fortinet gave no details about the exploit, noting it leaves no clear Indicators of Compromise (IoCs).
The flaw is an OS command injection flaw that could allow unauthenticated attackers to run arbitrary code or commands via crafted CLI requests.
“An improper neutralization of special elements used in an OS command (‘OS Command Injection’) vulnerability [CWE-78] in FortiSIEM may allow an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.” reads the advisory. “Practical exploit code for this vulnerability was found in the wild.”
The vulnerability impacts the following versions:
- FortiSIEM 6.1, 6.2, 6.3, 6.4, 6.5, 6.6 (Migrate to a fixed release)
- FortiSIEM 6.7.0 through 6.7.9 (Upgrade to 6.7.10 or above)
- FortiSIEM 7.0.0 through 7.0.3 (Upgrade to 7.0.4 or above)
- FortiSIEM 7.1.0 through 7.1.7 (Upgrade to 7.1.8 or above)
- FortiSIEM 7.2.0 through 7.2.5 (Upgrade to 7.2.6 or above)
- FortiSIEM 7.3.0 through 7.3.1 (Upgrade to 7.3.2 or above)
FortiSIEM 7.4 is not affected by the flaw.
As workarounds, the vendor recommends that customers limit access to the phMonitor port (7900).
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, FortiSIEM)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181104/hacking/critical-fortisiem-flaw-under-active-exploitation-fortinet-warns.html