HIGH🇵🇱 Wersja polska

CVE-2025-64153

CVSS 7.2v3.1pub. 2025-12-09

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Fortinet Fortiextender

    HW
    Fortinet
    all versions
  • Fortinet Fortiextender Firmware

    OS
    Fortinet
    7.0.0 – 7.0.47.2.0 – 7.2.57.4.0 – 7.4.77.6.0 – 7.6.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2024-23663HIGH8.8same product

An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0...

CVE-2022-23447HIGH7.5same product

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fo...

CVE-2022-27489HIGH7.2same product

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet Forti...

CVE-2021-41016HIGH7.8same product

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtende...

CVE-2025-46775MEDIUM5.5same product

A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1...