ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Fortinet warns about FortiSIEM vulnerability with in-the-wild exploit code (CVE-2025-25256)

criticalVulnerability exploited in the wildimportance 60CVE-2025-25256CVE-2023-34992CVE-2024-23108

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-34992
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized c

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

NVD description · AI analysis pending
9.880%
  • fortinet fortisiem
CVE-2024-23108
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

NVD description · AI analysis pending
9.878%
  • fortinet fortisiem
CVE-2025-25256
Unauthenticated OS command injection in Fortinet FortiSIEM (CVE-2025-25256)

CVE-2025-25256 is a critical (CVSS 9.8) OS command injection flaw (CWE-78) in Fortinet's FortiSIEM SIEM platform. An unauthenticated attacker can trigger it by sending specially crafted CLI requests over the network, which the appliance fails to properly neutralize before execution. Successful exploitation allows the attacker to execute unauthorized code or commands on the affected system without credentials or user interaction, effectively giving control of the appliance. Essentially every currently supported and many older FortiSIEM releases are affected, spanning versions 4.7 through 7.3.1. Fortinet has confirmed exploit code is being used in the wild, and the flaw carries a high 60.3% EPSS probability of exploitation within 30 days, though it is not yet in CISA's KEV catalog.

Do: Upgrade FortiSIEM to a fixed release per Fortinet's security advisory, ensuring the deployed version falls outside all affected ranges listed above; given in-the-wild exploitation and a ~60% EPSS probability, prioritize externally reachable instances. Until patched, restrict network access to the appliance's CLI/management-facing services and review logs for unexpected commands or connections that may indicate compromise.

9.860%
  • Fortinet FortiSIEM 7.3.0-7.3.1, 7.2.0-7.2.5, 7.1.0-7.1.7, 7.0.0-7.0.3, 6.7.0-6.7.9; 6.6, 6.5, 6.4, 6.3, 6.2, 6.1, 5.4, 5.3, 5.2, 5.1, 5.0, 4.10, 4.9, 4.7 (all versions)
largetens of thousands of deployed FortiSIEM instances worldwide (order-of-magnitude estimate)
Full article402 words · extracted from helpnetsecurity.com · click to collapse

Fortinet has released patches for a critical OS command injection vulnerability (CVE-2025-25256) in FortiSIEM, after practical exploit code surfaced in the wild.

FortiSIEM CVE-2025-25256 exploit

About CVE-2025-25256

FortiSIEM is a security information and event management platform used by organizations to collect, correlate and analyze logs, events, and alerts from across an organization’s IT and security infrastructure, to help detect threats and investigate incidents.

CVE-2025-25256 is caused by improper neutralization of special elements and may allow unauthenticated attackers to execute unauthorized code or commands on vulnerable devices via specially crafted command-line interface (CLI) requests. No user interaction is required to exploit the vulnerability.

The vulnerability affects FortiSIEM versions:

  • 7.3.0 through 7.3.1
  • 7.2.0 through 7.2.5
  • 7.1.0 through 7.1.7
  • 7.0.0 through 7.0.3
  • 6.7.0 through 6.7.9

Older branches – FortiSIEM 6.6, 6.5, 6.4, 6.3, 6.2, 6.1, and 5.4 – are also affected.

Admins are advised to upgrade to one of the following versions that include a fix:

  • FortiSIEM 7.4 (released in late July 2025)
  • FortiSIEM 7.3.2 or above
  • FortiSIEM 7.2.6 or above
  • FortiSIEM 7.1.8 or above
  • FortiSIEM 7.0.4 or above
  • FortiSIEM 6.7.10 or above

If a quick upgrade is impossible, Fortinet advises limiting access to the phMonitor port (TCP port 7900) only to trusted internal hosts/IPs. The port hosts the phMonitor service, which is used by internal FortiSIEM components to communicate and perform discovery and synchronization task.

Should you worry about the exploit code?

Fortinet did not share details about where the exploit code has been found or speculate about the possibility of it having been leveraged by attackers.

A little over a year ago, Horizon3.ai researches released PoC exploits for CVE-2023-34992 and its patch bypass CVE-2024-23108, which also relied on sending specially crafted messages to FortiSIEM’s phMonitor service on tcp/7900. Despite the PoCs’ availability, there have not been confirmed instances of them having been leveraged by attackers in the wild.

Unfortunately for defenders, the exploit code for CVE-2025-25256 “does not appear to produce distinctive [indicators of compromise]”, so it may be difficult to pinpoint intrusions made via this vulnerability.

UPDATE (August 18, 2025, 06:10 a.m. ET):

WatchTowr Labs researchers have published a technical write-up pinpointing the vulnerable function underpinning this vulnerability and have released an Detection Artifact Generator – i.e., a script – that attempts to detect whether a specific FortiSIEM instance is vulnerable to CVE-2025-25256.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/08/13/fortinet-warns-about-fortisiem-vulnerability-with-in-the-wild-exploit-code-cve-2025-25256/