CVE Vulnerabilities

CVE-2025-58325

Incorrect Provision of Specified Functionality

Published: Oct 14, 2025 | Modified: Oct 14, 2025
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI commands.

Weakness

The code does not function according to its published specifications, potentially leading to incorrect usage.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 6.4.0 (including) 7.0.16 (excluding)
Fortios Fortinet 7.2.0 (including) 7.2.11 (excluding)
Fortios Fortinet 7.4.0 (including) 7.4.6 (excluding)
Fortios Fortinet 7.6.0 (including) 7.6.0 (including)

Potential Mitigations

References