CVE-2025-64155

CRITICAL EXPLOITED

Fortinet Fortisiem < 7.1.9 - OS Command Injection

Title source: rule

Description

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.

Exploits (6)

nomisec WORKING POC 30 stars
by horizon3ai · remote
https://github.com/horizon3ai/CVE-2025-64155
github SCANNER 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2025/CVE-2025-64155
github SUSPICIOUS 2 stars
by exploitChains · pythonpoc
https://github.com/exploitChains/poc-collection/tree/main/CVE-2025-64155
nomisec SCANNER 1 stars
by cyberdudebivash · poc
https://github.com/cyberdudebivash/CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner
nomisec SCANNER
by purehate · remote
https://github.com/purehate/CVE-2025-64155-hunter
nomisec WRITEUP
by Mefhika120 · poc
https://github.com/Mefhika120/Ashwesker-CVE-2025-64155

Scores

CVSS v3 9.8
EPSS 0.0008
EPSS Percentile 23.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2026-01-15
CWE
CWE-78
Status published
Products (2)
fortinet/fortisiem 7.4.0
fortinet/fortisiem 6.7.0 - 7.1.9
Published Jan 13, 2026
Tracked Since Feb 18, 2026