CVE-2025-64155
CRITICAL EXPLOITEDFortinet Fortisiem < 7.1.9 - OS Command Injection
Title source: ruleDescription
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.
Exploits (6)
github
SCANNER
10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2025/CVE-2025-64155
github
SUSPICIOUS
2 stars
by exploitChains · pythonpoc
https://github.com/exploitChains/poc-collection/tree/main/CVE-2025-64155
nomisec
SCANNER
1 stars
by cyberdudebivash · poc
https://github.com/cyberdudebivash/CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner
Scores
CVSS v3
9.8
EPSS
0.0008
EPSS Percentile
23.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2026-01-15
CWE
CWE-78
Status
published
Products (2)
fortinet/fortisiem
7.4.0
fortinet/fortisiem
6.7.0 - 7.1.9
Published
Jan 13, 2026
Tracked Since
Feb 18, 2026