← Back

CVE-2025-47856

nvd nist
Published: Oct 14, 2025Modified: Oct 16, 2025

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: psirt@fortinet.com (Secondary)

Description

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.

Affected (3)

Products: Fortinet: Fortivoice
1 product
Fortivoice
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.4.0 to 6.4.11
From 7.0.0 to 7.0.7
Version 7.2.0

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.