Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Fortinet FortiSIEM — An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in For…
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .6034 99.1 —
AFFECTED
Product Versions Fixed
FortiSIEM 7.3.0 – —
TIMELINE
Feb 5 Reserved by fortinet
Aug 12 Published (CNA: fortinet)
Aug 18 EXPLOIT PUBLISHED — CVE-2025-25256 (Fortinet FortiSIEM). Public exploit reference added.
Description
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0.0 through 7.0.3, FortiSIEM 6.7.0 through 6.7.9, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions, FortiSIEM 6.3 all versions, FortiSIEM 6.2 all versions, FortiSIEM 6.1 all versions, FortiSIEM 5.4 all versions, FortiSIEM 5.3 all versions, FortiSIEM 5.2 all versions, FortiSIEM 5.1 all versions, FortiSIEM 5.0 all versions, FortiSIEM 4.10 all versions, FortiSIEM 4.9 all versions, FortiSIEM 4.7 all versions allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| February 5, 2025 | Reserved | Reserved by fortinet |
| August 12, 2025 | Published | Published (CNA: fortinet) |
| August 18, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2025-25256 (Fortinet FortiSIEM). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Fortinet | FortiSIEM | — | 7.3.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-25256 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.