CVE-2025-64156: SQL Injection
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7, FortiVoice 6.4 all versions, FortiVoice 6.0 all versions may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64156?
CVE-2025-64156 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2025-64156?
To fix CVE-2025-64156, update Fortinet FortiVoice to the latest available version, ideally beyond 7.2.1.
Who is affected by CVE-2025-64156?
CVE-2025-64156 affects FortiVoice versions 7.2.0 to 7.2.1, 7.0.0 to 7.0.7, along with all versions of 6.4 and 6.0.
Can CVE-2025-64156 be exploited remotely?
No, CVE-2025-64156 requires an authenticated privilege to exploit the SQL injection vulnerability.
What types of attacks can CVE-2025-64156 lead to?
CVE-2025-64156 can lead to unauthorized access to the database and manipulation of data.