logo

CVE-2023-25610 a critical RCE vulnerability in FortiOS: everything you need to know

ID: 3fab7d82-f304-5af7-aa4c-8d93ad5f7fa0

STIX ID: report--3fab7d82-f304-5af7-aa4c-8d93ad5f7fa0

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2023-03-13

Date Updated: 2026-05-01

...
...

**Executive Summary:** CVE-2023-25610 is a critical unauthenticated remote code execution (buffer underwrite) vulnerability in FortiOS and FortiProxy administrative interfaces affecting multiple major versions; a public proof-of-concept was published and Wiz reports ~9% of cloud enterprise environments are susceptible with many FortiOS instances unpatched, so operators should upgrade to the listed patched versions or apply the provided mitigation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.