CVE-2025-67862: Restricted CLI escape using Lua
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands.
Other sources
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0 all versions may allow an authenticated admin to execute lua scripts via crafted CLI commands.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 7.0.17 - Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 7.2.11 - Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 7.4.8 - Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 7.6.3 - Upgrade
Upgrade
Fortinet FortiProxyto a version that resolves this vulnerability.Fixed in 7.2.15 - Upgrade
Upgrade
Fortinet FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.11 - Upgrade
Upgrade
Fortinet FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67862?
CVE-2025-67862 has a medium severity rating of 6.7.
How do I fix CVE-2025-67862?
To fix CVE-2025-67862, upgrade to FortiOS version 7.6.3 or higher, or FortiProxy version 7.6.4 or higher.
What systems are affected by CVE-2025-67862?
CVE-2025-67862 affects Fortinet FortiOS and Fortinet FortiProxy.
What does CVE-2025-67862 exploit?
CVE-2025-67862 exploits an Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability.
Who can exploit CVE-2025-67862?
An authenticated admin can exploit CVE-2025-67862 to execute lua scripts via crafted CLI commands.