PT-2025-29458 · Fortinet · Fortivoice

Published

2025-07-14

·

Updated

2025-10-14

·

CVE-2025-47856

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fortinet FortiVoice versions 7.0.0 through 7.0.6 and 7.2.0 versions prior to 6.4.10
Description Two improper neutralization of special elements used in an OS command vulnerabilities exist. A privileged attacker can execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.
Recommendations Update FortiVoice to version 6.4.10 or later. Update FortiVoice to version 7.2.1 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-47856

Affected Products

Fortivoice