---
id: CVE-2025-47856
title: >-
  Two improper neutralization of special elements used in an OS command ('OS
  Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version
  7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to
  execute a…
summary: >-
  Two improper neutralization of special elements used in an OS command ('OS
  Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version
  7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to
  execute a…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: fortinet
product: fortivoice
affected:
  - 'fortivoice >= 6.4.0, < 6.4.11'
  - 'fortivoice >= 7.0.0, < 7.0.7'
  - fortivoice = 7.2.0
patched:
  - fortivoice 7.0.7
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-47856'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-25-250'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.01324
epssPercentile: 0.70053
ingestedAt: '2026-10-08T11:31:27.383Z'
---

## Overview

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.

## Affected

- `fortivoice >= 6.4.0, < 6.4.11`
- `fortivoice >= 7.0.0, < 7.0.7`
- `fortivoice = 7.2.0`

## Remediation

Upgrade past the affected range:

- `fortivoice 7.0.7`
