CVE-2025-47857: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47857?
CVE-2025-47857 has a high severity rating due to the potential for arbitrary code execution by an attacker.
How do I fix CVE-2025-47857?
To fix CVE-2025-47857, update the Fortinet FortiWeb CLI to version 7.6.4 or later.
Who is affected by CVE-2025-47857?
CVE-2025-47857 affects users of Fortinet FortiWeb CLI versions 7.6.0 to 7.6.3 and versions prior to 7.4.8.
What type of vulnerability is CVE-2025-47857?
CVE-2025-47857 is categorized as an OS command injection vulnerability.
What can an attacker do with CVE-2025-47857?
An attacker can execute arbitrary commands on the system through crafted CLI commands due to CVE-2025-47857.