CVE-2025-58325
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenti
Exploited
Not listed
EPSS
0.003
19.3th percentile
Discovered by
Vendor
Vendor advisory field
Published
Oct 14, 2025
Assigned by fortinet
Description
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI commands.
Weakness: CWE-684
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS Check your version | Firewall / NGFW | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiOS
Credit
Internally discovered and reported by Francois Ropert of Fortinet PSIRT team.
Vendor remediation
Upgrade to FortiOS version 7.6.1 or above Upgrade to FortiOS version 7.4.6 or above Upgrade to FortiOS version 7.2.11 or above Upgrade to FortiOS version 7.0.16 or above