PT-2025-47363 · Fortinet · Fortivoice

Published

2025-11-18

·

Updated

2025-11-19

·

CVE-2025-58692

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Fortinet FortiVoice versions 7.0.0 through 7.0.7 Fortinet FortiVoice versions 7.2.0 through 7.2.2
Description An SQL injection issue exists in Fortinet FortiVoice due to improper neutralization of special elements within SQL commands. An authenticated attacker can leverage this to execute unauthorized code or commands by sending specially crafted HTTP or HTTPS requests.
Recommendations Update Fortinet FortiVoice to a version later than 7.0.7. Update Fortinet FortiVoice to a version later than 7.2.2.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-14865
CVE-2025-58692

Affected Products

Fortivoice