logo

CVE-2025-64155: Critical FortiSIEM Flaw Allows Remote Root Access

ID: 811148df-3e8f-5854-a115-5a0d4fcf4546

STIX ID: report--811148df-3e8f-5854-a115-5a0d4fcf4546

Feed Name: SOCRadar Blog

Threat Score
78/100

Date Published: 2026-01-15

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Fortinet FortiSIEM is affected by a critical unauthenticated OS command injection (CVE-2025-64155, CVSS 9.8) in the phMonitor service (TCP 7900) that can lead to remote code execution and full system compromise via a writable admin-run script escalated to root; multiple 6.7.x–7.4.0 versions are impacted, Fortinet has released patches and guidance, a public PoC exists, and interim mitigation includes restricting access to port 7900 and reviewing logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.