---
id: CVE-2025-31104
title: >-
  A improper neutralization of special elements used in an os command ('os
  command injection') vulnerability in Fortinet FortiADC 7.6.0 through 7.6.1,
  FortiADC 7.4.0 through 7.4.6, FortiADC 7.2.0 through 7.2.7, FortiADC 7.1.0
  through 7.1.4…
summary: >-
  A improper neutralization of special elements used in an os command ('os
  command injection') vulnerability in Fortinet FortiADC 7.6.0 through 7.6.1,
  FortiADC 7.4.0 through 7.4.6, FortiADC 7.2.0 through 7.2.7, FortiADC 7.1.0
  through 7.1.4…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: fortinet
product: fortiadc
affected:
  - 'fortiadc >= 6.1.0, < 7.1.5'
  - 'fortiadc >= 7.2.0, < 7.2.8'
  - 'fortiadc >= 7.4.0, < 7.4.7'
  - 'fortiadc >= 7.6.0, < 7.6.2'
patched:
  - fortiadc 7.6.2
published: '2025-06-10'
updated: '2026-08-31'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-31104'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-25-099'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.01073
epssPercentile: 0.63473
ingestedAt: '2026-08-31T13:08:31.640Z'
---

## Overview

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiADC 7.6.0 through 7.6.1, FortiADC 7.4.0 through 7.4.6, FortiADC 7.2.0 through 7.2.7, FortiADC 7.1.0 through 7.1.4, FortiADC 7.0 all versions, FortiADC 6.2 all versions, FortiADC 6.1 all versions, FortiADC 6.0 all versions, FortiADC 5.4 all versions, FortiADC 5.3 all versions, FortiADC 5.2 all versions, FortiADC 5.1 all versions, FortiADC 5.0 all versions, FortiADC 4.8 all versions, FortiADC 4.7 all versions, FortiADC 4.6 all versions, FortiADC 4.5 all versions, FortiADC 4.4 all versions, FortiADC 4.3 all versions, FortiADC 4.2 all versions, FortiADC 4.1 all versions, FortiADC 4.0 all versions, FortiADC 3.2 all versions, FortiADC 3.1 all versions, FortiADC 3.0 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

## Affected

- `fortiadc >= 6.1.0, < 7.1.5`
- `fortiadc >= 7.2.0, < 7.2.8`
- `fortiadc >= 7.4.0, < 7.4.7`
- `fortiadc >= 7.6.0, < 7.6.2`

## Remediation

Upgrade past the affected range:

- `fortiadc 7.6.2`
