CVE advisoryCRITICAL
CVE-2025-25256
FortiSIEM Command Injection Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical OS command injection vulnerability exists in Fortinet FortiSIEM, allowing unauthenticated attackers to run unauthorized commands. This affects a security monitoring tool, and successful exploitation could compromise system integrity and availability. It's important to confirm if this technology is in use and