CVE-2025-64155
84Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 9.4epss 43%
from disclosure to weapon0 days
Published on NVDJan 13
1st PoCJan 13
VulnCheck+2d
exploitation probability
43%top 1% of all CVEs
observed exploitation
yesVulnCheck
6 public exploit(s)
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
Affected products
Fortinet · FortiSIEMpublic PoCs found — 6
cve_referencegithub.com/horizon3ai/CVE-2025-64155★ 32githubgithub.com/cyberdudebivash/CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner★ 1cve_referencegithub.com/purehate/CVE-2025-64155-hunter★ 0githubgithub.com/Mefhika120/Ashwesker-CVE-2025-64155★ 0vulncheckvulncheck.com/xdb/bd906a05caa9unverifiedvulncheckvulncheck.com/xdb/458a3b6ba23dunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.