CVE-2025-58692: SQL Injection
An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows an authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58692?
CVE-2025-58692 has a medium severity rating due to its potential for unauthorized code execution.
How do I fix CVE-2025-58692?
To fix CVE-2025-58692, upgrade Fortinet FortiVoice to version 7.2.3 or later.
Who is affected by CVE-2025-58692?
CVE-2025-58692 affects authenticated users of Fortinet FortiVoice versions 7.2.0 to 7.2.2 and 7.0.0 to 7.0.7.
What type of vulnerability is CVE-2025-58692?
CVE-2025-58692 is an SQL Injection vulnerability, which allows attackers to manipulate SQL queries.
What impact does CVE-2025-58692 have?
CVE-2025-58692 can allow an attacker to execute unauthorized commands on affected Fortinet FortiVoice systems.