{"id":"CVE-2025-47856","title":"Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute a…","summary":"Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute a…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"fortinet","product":"fortivoice","affected":["fortivoice >= 6.4.0, < 6.4.11","fortivoice >= 7.0.0, < 7.0.7","fortivoice = 7.2.0"],"patched":["fortivoice 7.0.7"],"published":"2025-10-14","updated":"2026-10-08","sourceUpdated":"2026-10-08T12:10:00.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-47856","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-25-250","label":"psirt@fortinet.com"}],"tags":["nvd"],"epss":0.01324,"epssPercentile":0.70053,"ingestedAt":"2026-10-08T11:31:27.383Z","slug":"CVE-2025-47856","body":"## Overview\n\nTwo improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.\n\n## Affected\n\n- `fortivoice >= 6.4.0, < 6.4.11`\n- `fortivoice >= 7.0.0, < 7.0.7`\n- `fortivoice = 7.2.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fortivoice 7.0.7`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}