logo

Fortinet Critical Alert: CVE-2025-64155 RCE & Config Leaks Exposed

ID: 270a4bb0-72c2-51b1-b463-d9a775d8365d

STIX ID: report--270a4bb0-72c2-51b1-b463-d9a775d8365d

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Fortinet published security advisories for multiple critical vulnerabilities across FortiSIEM, FortiOS/FortiSwitch Manager, FortiFone, and other products—most notably CVE-2025-64155 (FortiSIEM OS command injection, CVSS 9.4) and CVE-2025-47855 (FortiFone info disclosure, CVSS 9.3). The flaws permit unauthenticated remote code execution, sensitive config disclosure, file deletion, SQL injection, and SSRF; Fortinet released fixed versions and provided mitigation guidance (restricting ports, removing fabric access, or upgrading to specified patched releases).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.