CVE-2025-31104: OS Command Injection
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 through 7.2.7, 7.1.0 through 7.1.4, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated attacker to execute unauthorized code via crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31104?
The severity of CVE-2025-31104 is classified as high, due to its potential for OS command injection.
How do I fix CVE-2025-31104?
To mitigate CVE-2025-31104, upgrade FortiADC to the latest version beyond 7.6.1, 7.4.6, 7.2.7, 7.1.4, and any versions of 7.0 and earlier.
Who is affected by CVE-2025-31104?
CVE-2025-31104 affects FortiADC versions from 6.1 through 7.6.1.
What types of vulnerabilities does CVE-2025-31104 include?
CVE-2025-31104 includes an improper neutralization vulnerability that can lead to OS command injection.
Can CVE-2025-31104 be exploited remotely?
Yes, CVE-2025-31104 can be exploited by an authenticated attacker who has access to the affected FortiADC systems.