Home Fortinet CVE-2025-47856
Back to Fortinet

CVE-2025-47856

FortiVoice - Web UI

Fortinet CVSS 7.2 Updated March 16, 2026

Executive Risk Summary

"Two OS Command Injection vulnerabilities in FortiVoice versions 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allow a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests. Successful exploitation could lead to complete system compromise, data breaches, and disruption of critical services."

Operational Audit Arsenal

Target Type Firmware Image
Target Asset FortiVoice Firmware
Standard Path Global Firmware

Manual Verification Required

This is a non-Windows asset (Fortinet). Use the target asset details above to verify your version against vendor advisories.

Patch Impact Forecast

Reboot Required Likely

Moderate to High

Internal Work Notes

CVE-2025-47856: FortiVoice OS Command Injection vulnerability - Upgrade to a patched version (>= 6.4.10 or >= 7.0.7) to prevent arbitrary code execution and system compromise.

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Scope of Impact

Fortinet FortivoiceFortinet Fortivoice (Version 7.2.0)

Original NVD Description

"Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests."

Related Fortinet Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.