CVE-2025-58325

An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenti

Severity
High 7.8
CVSS 3.1
Adjacent, local or physical access what this means
Exploited
Not listed
EPSS
0.003
19.3th percentile
Discovered by
Vendor
Vendor advisory field
Published
Oct 14, 2025
Assigned by fortinet

Description

An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI commands.

Weakness: CWE-684

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Check your version Firewall / NGFW cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiOS

Credit

Internally discovered and reported by Francois Ropert of Fortinet PSIRT team.

Vendor remediation

Upgrade to FortiOS version 7.6.1 or above Upgrade to FortiOS version 7.4.6 or above Upgrade to FortiOS version 7.2.11 or above Upgrade to FortiOS version 7.0.16 or above

Something wrong here?