FortiOS CLI Command Bypass Vulnerability Let Attacker Execute System Commands
On Sat, Oct 14, 2025, Fortinet disclosed a high-severity vulnerability in its FortiOS operating system. This flaw allows local authenticated users to execute arbitrary system commands.
On Sat, Oct 14, 2025, Fortinet disclosed a high-severity vulnerability in its FortiOS operating system. This flaw allows local authenticated users to execute arbitrary system commands.
The vulnerability, identified as CVE-2025-58325, results from an incorrect provision of specified functionality (CWE-684) within the CLI component. This flaw creates a potential for privilege escalation.
With a CVSS v3.1 score of 7.8 (AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H), the vulnerability poses significant risks to enterprise networks utilizing Fortinet's firewalls and security appliances.
FortiOS CLI Command Bypass Vulnerability
The issue is triggered when a local attacker with high privileges executes malicious CLI commands, bypassing intended restrictions and performing unauthorized system-level operations. The vulnerability could lead to full control over the device, data exfiltration, or further network compromise. Although remote exploitation is not possible, the low attack complexity and high impact make it a noteworthy target for insiders or compromised accounts.
Affected Platforms and Recommendations
The flaw was discovered by Francois Ropert from Fortinet's PSIRT team. Affected platforms include high-end models such as the 100E/101E series up to the 7000F, while other models remain unaffected.
Organizations should immediately verify their setups, as exploitation requires only local access and no user interaction. Fortinet advises upgrading to patched releases. Below is a summary of impacted versions and recommended solutions:
On Sat, Oct 14, 2025, Fortinet disclosed a high-severity vulnerability in its FortiOS operating system.
FortiOS Version Affected Builds Recommended Solution
7.6 7.6.0 Upgrade to 7.6.1 or above
7.4 7.4.0 through 7.4.5 Upgrade to 7.4.6 or above
7.2 7.2.0 through 7.2.10 Upgrade to 7.2.11 or above
7.0 7.0.0 through 7.0.15 Upgrade to 7.0.16 or above
6.4 All versions Migrate to a fixed release
Organizations should utilize Fortinet's upgrade path tool for seamless transitions. Although no indicators of compromise (IoCs) or proof-of-concept exploits have been released, monitoring CLI logs for anomalies is recommended.
This incident, identified as FG-IR-24-361, emphasizes the importance of enforcing least-privilege access in CLI management.
For more information, visit the Fortinet PSIRT page .
Based on reporting by Cyber Security News.
