CVE-2025-64155

CRITICAL EXPLOITED

Fortinet Fortisiem < 7.1.9 - OS Command Injection

Title source: rule

Description

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.

Exploits (6)

nomisec WORKING POC 30 stars
by horizon3ai · remote
https://github.com/horizon3ai/CVE-2025-64155
github SCANNER 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2025/CVE-2025-64155
github SUSPICIOUS 2 stars
by exploitChains · pythonpoc
https://github.com/exploitChains/poc-collection/tree/main/CVE-2025-64155
nomisec SCANNER 1 stars
by cyberdudebivash · poc
https://github.com/cyberdudebivash/CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner
nomisec SCANNER
by purehate · remote
https://github.com/purehate/CVE-2025-64155-hunter
nomisec WRITEUP
by Mefhika120 · poc
https://github.com/Mefhika120/Ashwesker-CVE-2025-64155

Scores

CVSS v3 9.8
EPSS 0.0004
EPSS Percentile 12.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2026-01-15

Classification

CWE
CWE-78
Status published

Affected Products (2)

fortinet/fortisiem < 7.1.9
fortinet/fortisiem

Timeline

Published Jan 13, 2026
Tracked Since Feb 18, 2026