Multiple Vulnerabilities in Fortinet Products Could Allow for Remote Code Execution
ID: 28bb4737-6061-51d3-bacf-660dff3fc450
STIX ID: report--28bb4737-6061-51d3-bacf-660dff3fc450
Feed Name: CISecurity.org Advisories
Multiple vulnerabilities were disclosed in Fortinet products, the most severe being an unauthenticated OS command injection in FortiSIEM (CVE-2025-25256) that can permit remote code execution. The advisory also lists other high- and medium-severity issues—path traversal, privilege escalation, double free, integer overflow, and auth bypass—affecting FortiManager, FortiOS, FortiProxy, and FortiPAM, and maps these flaws to Initial Access and Exploitation of Public-Facing Application techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
