CVE-2025-47856: Command injection vulnerability
Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.
Other sources
Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in FortiVoice may allow a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiVoiceto a version that resolves this vulnerability.Fixed in 6.4.11 - Upgrade
Upgrade
FortiVoiceto a version that resolves this vulnerability.Fixed in 7.0.7 - Upgrade
Upgrade
FortiVoiceto a version that resolves this vulnerability.Fixed in 7.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47856?
CVE-2025-47856 has a high severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2025-47856?
To fix CVE-2025-47856, upgrade your FortiVoice software to version 7.2.1 or later, or apply the appropriate patches for earlier versions.
What is affected by CVE-2025-47856?
CVE-2025-47856 affects FortiVoice software versions before 7.2.1, as well as 7.0.6 and 6.4.10 and earlier.
Who can exploit CVE-2025-47856?
CVE-2025-47856 can be exploited by a privileged attacker with access to execute crafted HTTP/HTTPS or CLI requests.
What type of vulnerability is CVE-2025-47856?
CVE-2025-47856 is classified as an OS Command Injection vulnerability, specifically involving improper neutralization of special elements.