Fortinet Product Security Update Advisory (CVE-2025-25256)
Overview
We have released security updates to fix vulnerabilities in Fortinet products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-25256
FortiSIEM Versions: 7.3.0 and later and 7.3.1 and earlier
FortiSIEM Versions: 7.2.0 and earlier and 7.2.5 and earlier
FortiSIEM version: 7.1.0 or later and 7.1.7 or earlier
FortiSIEM version: 7.0.0 or later and 7.0.3 or earlier
FortiSIEM version: 6.7.0 or later and 6.7.9 or earlier
FortiSIEM version: 6.6 all versions
FortiSIEM Version: 6.5 All Versions
FortiSIEM Versions: 6.4 All Versions
FortiSIEM Version : 6.3 All Versions
FortiSIEM Version : 6.2 All Versions
FortiSIEM Version : 6.1 All Versions
FortiSIEM Version: 5.4 All Versions
Resolved Vulnerabilities
Command Injection Vulnerability in Fortinet’s FortiSIEM (CVE-2025-25256)
Vulnerability Patches
Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-25256
FortiSIEM Version: 7.3.2 and later
FortiSIEM Version: 7.2.6 and later
FortiSIEM Version: 7.1.8 and later
FortiSIEM Version: 7.0.4 and later
FortiSIEM version: 6.7.10 and later
FortiSIEM versions 5.4 and earlier and 6.6 and earlier: Migrating to a fixed release (7.4 and later, 7.3.2 and later, 7.2.6 and later, 7.1.8 and later, 7.0.4 and later, 6.7.10 and later)
References
[1] Remote unauthenticated command injection
https://fortiguard.fortinet.com/psirt/FG-IR-25-152