Fortinet Product Security Update Advisory (CVE-2025-25256)

Fortinet Product Security Update Advisory (CVE-2025-25256)

Overview

 

We have released security updates to fix vulnerabilities in Fortinet products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-25256

 

FortiSIEM Versions: 7.3.0 and later and 7.3.1 and earlier
FortiSIEM Versions: 7.2.0 and earlier and 7.2.5 and earlier
FortiSIEM version: 7.1.0 or later and 7.1.7 or earlier
FortiSIEM version: 7.0.0 or later and 7.0.3 or earlier
FortiSIEM version: 6.7.0 or later and 6.7.9 or earlier
FortiSIEM version: 6.6 all versions
FortiSIEM Version: 6.5 All Versions
FortiSIEM Versions: 6.4 All Versions
FortiSIEM Version : 6.3 All Versions
FortiSIEM Version : 6.2 All Versions
FortiSIEM Version : 6.1 All Versions
FortiSIEM Version: 5.4 All Versions

 

 

Resolved Vulnerabilities

 

Command Injection Vulnerability in Fortinet’s FortiSIEM (CVE-2025-25256)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2025-25256

 

FortiSIEM Version: 7.3.2 and later
FortiSIEM Version: 7.2.6 and later
FortiSIEM Version: 7.1.8 and later
FortiSIEM Version: 7.0.4 and later
FortiSIEM version: 6.7.10 and later
FortiSIEM versions 5.4 and earlier and 6.6 and earlier: Migrating to a fixed release (7.4 and later, 7.3.2 and later, 7.2.6 and later, 7.1.8 and later, 7.0.4 and later, 6.7.10 and later)

 

 

References

 

[1] Remote unauthenticated command injection
https://fortiguard.fortinet.com/psirt/FG-IR-25-152