---
id: CVE-2025-25256
title: >-
  An improper neutralization of special elements used in an OS command ('OS
  Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM
  7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through
  7.1.7, F…
summary: >-
  An improper neutralization of special elements used in an OS command ('OS
  Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM
  7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through
  7.1.7, F…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: fortinet
product: fortisiem
affected:
  - 'fortisiem >= 5.4.0, < 6.7.10'
  - 'fortisiem >= 7.0.0, < 7.0.4'
  - 'fortisiem >= 7.1.0, < 7.1.8'
  - 'fortisiem >= 7.2.0, < 7.2.6'
  - 'fortisiem >= 7.3.0, < 7.3.2'
patched:
  - fortisiem 7.3.2
published: '2025-08-12'
updated: '2026-08-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-25256'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-25-152'
    label: psirt@fortinet.com
  - url: 'https://www.theregister.com/2025/08/13/fortinet_discloses_critical_bug/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/watchtowrlabs/watchTowr-vs-FortiSIEM-CVE-2025-25256'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://labs.watchtowr.com/should-security-solutions-be-secure-maybe-were-all-wrong-fortinet-fortisiem-pre-auth-command-injection-cve-2025-25256/
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.64704
epssPercentile: 0.99218
ingestedAt: '2026-08-18T21:22:57.552Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/watchtowrlabs/watchTowr-vs-FortiSIEM-CVE-2025-25256'
  nuclei:
    - network/cves/2025/CVE-2025-25256
  checkedAt: '2026-09-25T08:20:44.823Z'
exploitAvailable: true
---

## Overview

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0.0 through 7.0.3, FortiSIEM 6.7.0 through 6.7.9, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions, FortiSIEM 6.3 all versions, FortiSIEM 6.2 all versions, FortiSIEM 6.1 all versions, FortiSIEM 5.4 all versions, FortiSIEM 5.3 all versions, FortiSIEM 5.2 all versions, FortiSIEM 5.1 all versions, FortiSIEM 5.0 all versions, FortiSIEM 4.10 all versions, FortiSIEM 4.9 all versions, FortiSIEM 4.7 all versions allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.

## Affected

- `fortisiem >= 5.4.0, < 6.7.10`
- `fortisiem >= 7.0.0, < 7.0.4`
- `fortisiem >= 7.1.0, < 7.1.8`
- `fortisiem >= 7.2.0, < 7.2.6`
- `fortisiem >= 7.3.0, < 7.3.2`

## Remediation

Upgrade past the affected range:

- `fortisiem 7.3.2`
