CVE-2025-64155
CRITICAL EXPLOITEDFortinet Fortisiem < 7.1.9 - OS Command Injection
Title source: ruleDescription
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.
Exploits (6)
github
SCANNER
10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2025/CVE-2025-64155
github
SUSPICIOUS
2 stars
by exploitChains · pythonpoc
https://github.com/exploitChains/poc-collection/tree/main/CVE-2025-64155
nomisec
SCANNER
1 stars
by cyberdudebivash · poc
https://github.com/cyberdudebivash/CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner
Scores
CVSS v3
9.8
EPSS
0.0004
EPSS Percentile
12.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
VulnCheck KEV
2026-01-15
Classification
CWE
CWE-78
Status
published
Affected Products (2)
fortinet/fortisiem
< 7.1.9
fortinet/fortisiem
Timeline
Published
Jan 13, 2026
Tracked Since
Feb 18, 2026