CVE-2025-58325: Restricted CLI command bypass
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow a local authenticated attacker to execute system commands via crafted CLI commands.
Other sources
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS may allow a local authenticated attacker to execute system commands via crafted CLI commands.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58325?
The severity of CVE-2025-58325 is classified as critical due to its potential for local authenticated attackers to execute system commands.
How do I fix CVE-2025-58325?
To fix CVE-2025-58325, upgrade your FortiOS to the latest version that addresses the vulnerability.
Which versions of FortiOS are affected by CVE-2025-58325?
CVE-2025-58325 affects FortiOS versions 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, and all versions of 6.4.
Can CVE-2025-58325 be exploited remotely?
CVE-2025-58325 cannot be exploited remotely as it requires local authenticated access to execute commands.
What type of attacks can CVE-2025-58325 enable?
CVE-2025-58325 can enable local authenticated attackers to execute arbitrary system commands via crafted CLI commands.