Critical FortiSIEM Vulnerability(CVE-2025-64155) Enable Full RCE and Root Compromise
ID: d41b9db2-79c1-588a-bbfa-c38d33eecb21
STIX ID: report--d41b9db2-79c1-588a-bbfa-c38d33eecb21
Feed Name: cybersecurityNews.com
Fortinet FortiSIEM is affected by an unauthenticated OS command injection (CVE-2025-64155/CVE-2025-25256) that allows attackers to inject arguments into a curl-based script to overwrite binaries (e.g., phLicenseTool) and obtain admin shells; those admin shells can then escalate to root by overwriting a writable root cron job. A public proof-of-concept exploit is available, practical exploitation was observed, and threat actors (including mentions in leaked Black Basta chats) have shown interest; Fortinet has released patches and advises upgrades and port 7900 restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
