Critical FortiSIEM Vulnerability(CVE-2025-64155) Enable Full RCE and Root Compromise
On Thu, Aug 7, 2025, Fortinet released an advisory for CVE-2025-25256 , detailing an OS command injection vulnerability (CWE-78) in FortiSIEM. This issue allows unauthenticated remote code execution through specially crafted CLI requests.
On Thu, Aug 7, 2025, Fortinet released an advisory for CVE-2025-25256 , detailing an OS command injection vulnerability (CWE-78) in FortiSIEM. This issue allows unauthenticated remote code execution through specially crafted CLI requests.
An investigation by Horizon3.ai identified a vulnerability chain facilitating remote code execution and privilege escalation. This chain exploits an unauthenticated argument injection vulnerability to achieve arbitrary file writes and admin-level remote code execution, which then escalates to root access via file overwrite.
Fortinet assigned CVE-2025-64155 to these vulnerabilities, documented under FG-IR-25-772. A proof-of-concept exploit is available on GitHub .
FortiSIEM Architecture and Vulnerabilities
FortiSIEM can be deployed as all-in-one servers or in supervisor-collector models. The phMonitor service manages communication over TCP/IP port 7900 without authentication, processing custom API messages. Despite some security hardening, vulnerabilities remain.
The CVE-2025-64155 vulnerability targets the handleStorageRequest function with the "elastic" storage type, allowing user-controlled XML tags to trigger argument injection in the elastic_test_url.sh script. This leads to unauthorized file overwrites and admin access exploitation.
Version Affected Solution
On Thu, Aug 7, 2025, Fortinet released an advisory for CVE-2025-25256 , detailing an OS command injection vulnerability (CWE-78) in FortiSIEM.
7.4 Not affected N/A
7.3 7.3.0-7.3.1 Upgrade to 7.3.2+
7.2 7.2.0-7.2.5 Upgrade to 7.2.6+
7.1 7.1.0-7.1.7 Upgrade to 7.1.8+
7.0 7.0.0-7.0.3 Upgrade to 7.0.4+
6.7 6.7.0-6.7.9 Upgrade to 6.7.10+
6.6 and below All versions Migrate to fixed release
Administrators should monitor /opt/phoenix/log/phoenix.logs for PHL_ERROR entries indicating abuse of elastic_test_url.sh. This includes malicious URLs and target files, such as phLicenseTool overwrites.
Fortinet recommends upgrading vulnerable systems and restricting port 7900 access. Organizations should also audit logs and apply patches promptly to mitigate the risk of exploitation.
Based on reporting by Cyber Security News.
