CVE Vulnerabilities

CVE-2025-58325

Incorrect Provision of Specified Functionality

Published: Oct 14, 2025 | Modified: Oct 14, 2025
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI commands.

Weakness

The code does not function according to its published specifications, potentially leading to incorrect usage.

Affected Software

NameVendorStart VersionEnd Version
FortiosFortinet6.4.0 (including)7.0.16 (excluding)
FortiosFortinet7.2.0 (including)7.2.11 (excluding)
FortiosFortinet7.4.0 (including)7.4.6 (excluding)
FortiosFortinet7.6.0 (including)7.6.0 (including)

Potential Mitigations

References