logo

Fortinet fixed two critical flaws in FortiFone and FortiSIEM

ID: 0531bece-8888-5295-ab6e-3433dd9459c8

STIX ID: report--0531bece-8888-5295-ab6e-3433dd9459c8

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-01-14

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Fortinet released patches for six vulnerabilities, including two critical unauthenticated flaws: CVE-2025-64155 (FortiSIEM — OS command injection enabling unauthenticated remote code execution via crafted TCP requests) and CVE-2025-47855 (FortiFone — unauthenticated exposure of device configuration via crafted HTTP/HTTPS requests). The advisory lists affected FortiSIEM and FortiFone versions and recommended upgrade paths, notes mitigation suggestions (e.g., limit access to phMonitor port 7900), identifies the reporting researchers, and states there is no clear evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.