CVE-2025-64155

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.4.0:*:*:*:*:*:*:*

History

20 Jan 2026, 16:16

Type Values Removed Values Added
References
  • () https://github.com/purehate/CVE-2025-64155-hunter -
Summary
  • (es) Una vulnerabilidad de neutralización inadecuada de elementos especiales utilizados en un comando de sistema operativo ('inyección de comandos de sistema operativo') en Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 a 7.3.4, FortiSIEM 7.1.0 a 7.1.8, FortiSIEM 7.0.0 a 7.0.4, FortiSIEM 6.7.0 a 6.7.10 puede permitir a un atacante ejecutar código o comandos no autorizados a través de solicitudes TCP manipuladas.

14 Jan 2026, 21:37

Type Values Removed Values Added
References () https://fortiguard.fortinet.com/psirt/FG-IR-25-772 - () https://fortiguard.fortinet.com/psirt/FG-IR-25-772 - Vendor Advisory
References () https://github.com/horizon3ai/CVE-2025-64155 - () https://github.com/horizon3ai/CVE-2025-64155 - Exploit, Third Party Advisory
CPE cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisiem:7.4.0:*:*:*:*:*:*:*
First Time Fortinet
Fortinet fortisiem

13 Jan 2026, 20:16

Type Values Removed Values Added
References
  • () https://github.com/horizon3ai/CVE-2025-64155 -

13 Jan 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 17:15

Updated : 2026-01-20 16:16


NVD link : CVE-2025-64155

Mitre link : CVE-2025-64155

CVE.ORG link : CVE-2025-64155


JSON object : View

Products Affected

fortinet

  • fortisiem
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')