CVE-2025-31104: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiADC 7.6.0 through 7.6.1, FortiADC 7.4.0 through 7.4.6, FortiADC 7.2.0 through 7.2.7, FortiADC 7.1.0 through 7.1.4, FortiADC 7.0 all versions, FortiADC 6.2 all versions, FortiADC 6.1 all versions, FortiADC 6.0 all versions, FortiADC 5.4 all versions, FortiADC 5.3 all versions, FortiADC 5.2 all versions, FortiADC 5.1 all versions, FortiADC 5.0 all versions, FortiADC 4.8 all versions, FortiADC 4.7 all versions, FortiADC 4.6 all versions, FortiADC 4.5 all versions, FortiADC 4.4 all versions, FortiADC 4.3 all versions, FortiADC 4.2 all versions, FortiADC 4.1 all versions, FortiADC 4.0 all versions, FortiADC 3.2 all versions, FortiADC 3.1 all versions, FortiADC 3.0 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiADCto a version that resolves this vulnerability.Fixed in 7.1.5 - Upgrade
Upgrade
Fortinet FortiADCto a version that resolves this vulnerability.Fixed in 7.2.8 - Upgrade
Upgrade
Fortinet FortiADCto a version that resolves this vulnerability.Fixed in 7.4.7 - Upgrade
Upgrade
Fortinet FortiADCto a version that resolves this vulnerability.Fixed in 7.6.2 - Upgrade
Upgrade
Fortinet FortiADCto a version that resolves this vulnerability.Fixed in 8.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31104?
The severity of CVE-2025-31104 is classified as high, due to its potential for OS command injection.
How do I fix CVE-2025-31104?
To mitigate CVE-2025-31104, upgrade FortiADC to the latest version beyond 7.6.1, 7.4.6, 7.2.7, 7.1.4, and any versions of 7.0 and earlier.
Who is affected by CVE-2025-31104?
CVE-2025-31104 affects FortiADC versions from 6.1 through 7.6.1.
What types of vulnerabilities does CVE-2025-31104 include?
CVE-2025-31104 includes an improper neutralization vulnerability that can lead to OS command injection.
Can CVE-2025-31104 be exploited remotely?
Yes, CVE-2025-31104 can be exploited by an authenticated attacker who has access to the affected FortiADC systems.