ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

PoC exploit for critical FortiSIEM vulnerability released (CVE-2025-64155)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25256
Unauthenticated OS command injection in Fortinet FortiSIEM (CVE-2025-25256)

CVE-2025-25256 is a critical (CVSS 9.8) OS command injection flaw (CWE-78) in Fortinet's FortiSIEM SIEM platform. An unauthenticated attacker can trigger it by sending specially crafted CLI requests over the network, which the appliance fails to properly neutralize before execution. Successful exploitation allows the attacker to execute unauthorized code or commands on the affected system without credentials or user interaction, effectively giving control of the appliance. Essentially every currently supported and many older FortiSIEM releases are affected, spanning versions 4.7 through 7.3.1. Fortinet has confirmed exploit code is being used in the wild, and the flaw carries a high 60.3% EPSS probability of exploitation within 30 days, though it is not yet in CISA's KEV catalog.

Do: Upgrade FortiSIEM to a fixed release per Fortinet's security advisory, ensuring the deployed version falls outside all affected ranges listed above; given in-the-wild exploitation and a ~60% EPSS probability, prioritize externally reachable instances. Until patched, restrict network access to the appliance's CLI/management-facing services and review logs for unexpected commands or connections that may indicate compromise.

9.860%
  • Fortinet FortiSIEM 7.3.0-7.3.1, 7.2.0-7.2.5, 7.1.0-7.1.7, 7.0.0-7.0.3, 6.7.0-6.7.9; 6.6, 6.5, 6.4, 6.3, 6.2, 6.1, 5.4, 5.3, 5.2, 5.1, 5.0, 4.10, 4.9, 4.7 (all versions)
largetens of thousands of deployed FortiSIEM instances worldwide (order-of-magnitude estimate)
CVE-2025-64155
Unauthenticated RCE via OS Command Injection in Fortinet FortiSIEM

Fortinet FortiSIEM contains an unauthenticated OS command injection flaw (CWE-78) caused by improper neutralization of special elements used in an OS command. A remote attacker can trigger it by sending crafted TCP requests to the vulnerable service, requiring no credentials or user interaction. Successful exploitation allows execution of unauthorized code or commands on the SIEM host, giving an attacker control over a high-value security monitoring platform. Every current FortiSIEM release branch is affected: 7.4.0, 7.3.0 through 7.3.4, 7.1.0 through 7.1.8, 7.0.0 through 7.0.4, and 6.7.0 through 6.7.10. A public proof-of-concept exploit has been released, and EPSS assigns a 43.2% probability of exploitation within 30 days (99th percentile), though the flaw is not yet in CISA KEV and no confirmed in-the-wild exploitation has been reported.

Do: Upgrade FortiSIEM to the fixed release specified in Fortinet's advisory for CVE-2025-64155 as soon as possible, since exploitation requires only network reachability and no authentication. Until patched, restrict access to FortiSIEM's network-facing TCP services (management and event-ingestion interfaces) to trusted management networks and sources. Given the public proof-of-concept and high EPSS score, prioritize checking internet-exposed FortiSIEM instances for signs of exploitation and review logs for unexpected command execution.

9.845% PoC
  • Fortinet FortiSIEM 7.4.0
  • Fortinet FortiSIEM 7.3.0 - 7.3.4
  • Fortinet FortiSIEM 7.1.0 - 7.1.8
  • +2 more
largetens of thousands of FortiSIEM deployments worldwide (all current 6.7.x-7.4.x release branches affected)
Full article366 words · extracted from helpnetsecurity.com · click to collapse

A critical vulnerability (CVE-2025-64155) in Fortinet’s FortiSIEM security platform has now been accompanied by publicly released proof-of-concept (PoC) exploit code, raising the urgency for organizations to patch immediately.

About CVE-2025-64155

CVE-2025-64155 may allow unauthenticated, remote attackers to execute unauthorized code or commands on vulnerable FortiSIEM deployments via specially crafted TCP requests.

“This flaw targets the phMonitor service, the ‘nervous system’ of the SIEM, allowing attackers to write arbitrary code into a file executed as the root user, gaining unauthenticated code execution,” Scott Caveza, senior staff research engineer at Tenable, told Help Net Security.

“In effect, it turns a company’s defensive headquarters into a silent staging ground for lateral movement.”

Discovered and privately reported by Horizon3.ai researcher Zach Hanley, CVE-2025-64155 has been fixed in all affected supported versions of FortiSIEM and its existence publicly revealed by Fortinet earlier this week.

Customers using vulnerable FortiSIEM versions have been advised to upgrade to v7.4.1 or above, 7.3.5 or above, 7.2.7 or above, or 7.1.9 or above. Those still running FortiSIEM 7.0.x or 6.7.x versions have been advised to migrate to one of the fixed releases.

If upgrading to a fixed version is impossible, admins should limit access to the phMonitor port (7900).

CVE-2025-64155 does not affect FortiSIEM Cloud or FortiSIEM 7.5. It also doesn’t affect all nodes in a FortiSIEM deployment: Supervisor and Worker nodes are affected, but Collector nodes (used for log ingestion) aren’t.

Indicators of compromise to look for

Hanley unearthed CVE-2025-64155 while assessing a previously fixed FortiSIEM flaw (CVE-2025-25256) with practical exploit code spotted in the wild.

Fortinet never said whether they detected this exploit being used by attackers, possibly because exploitation of CVE-2025-25256 does not appear to produce distinctive indicators of compromise.

A successful exploitation of CVE-2025-64155, though, will leave traces.

According to Horizon3.ai researchers, defenders can check logs for suspicious messages received by phMonitor: messages with PHL_ERROR entries and containing attacker-supplied URLs and file paths where the malicious payload is written.

UPDATE (January 16, 2026, 03:25 p.m. ET):

Attempted exploitation of this vulnerability has been detected by threat intelligence firm Defused.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/01/15/fortisiem-vulnerability-cve-2025-64155-poc-exploit/