---
id: CVE-2025-58325
title: >-
  An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in
  FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through
  7.0.15, 6.4 all versions may allow a local authenticated attacker to execute
  system comm…
summary: >-
  An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in
  FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through
  7.0.15, 6.4 all versions may allow a local authenticated attacker to execute
  system comm…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-684
vendor: fortinet
product: fortios
affected:
  - 'fortios >= 6.4.0, < 7.0.16'
  - 'fortios >= 7.2.0, < 7.2.11'
  - 'fortios >= 7.4.0, < 7.4.6'
  - fortios = 7.6.0
patched:
  - fortios 7.4.6
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-58325'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-24-361'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.00287
epssPercentile: 0.19423
ingestedAt: '2026-10-08T11:31:27.391Z'
---

## Overview

An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI commands.

## Affected

- `fortios >= 6.4.0, < 7.0.16`
- `fortios >= 7.2.0, < 7.2.11`
- `fortios >= 7.4.0, < 7.4.6`
- `fortios = 7.6.0`

## Remediation

Upgrade past the affected range:

- `fortios 7.4.6`
