Technical details and a public exploit code have been published for a critical vulnerability affecting Fortinet 's FortiSIEM solution . The vulnerability could be exploited by a remote, unauthorized attacker to execute arbitrary commands or code.

The vulnerability is tracked as CVE-2025-25256 and is a combination of two issues that allow arbitrary registration with administrator privileges and privilege escalation to root access.
Researchers at Horizon3.ai reported the security issue in mid-August 2025. In early November, Fortinet addressed it in four of the product's five development branches and has now announced that all vulnerable versions have been patched.
See also: Spring vulnerability allows commands to be executed on the user's PC
The company describes the vulnerability as “improper neutralization of special elements used in an OS command vulnerability in FortiSIEM, which could allow an unauthenticated attacker to execute code or commands via crafted TCP requests.”

Horizon3.ai has published a detailed analysis explaining that the root of the problem is the exposure of dozens of command handlers in the phMonitor service, which can be invoked remotely without authentication. The researchers report that this service has been the entry point for multiple FortiSIEM vulnerabilities over the years, such as CVE-2023-34992 and CVE-2024-23108, and highlight that ransomware groups, such as Black Basta, have shown interest in these weaknesses.
Along with the technical details for CVE-2025-25256, the researchers have also published a demonstrative exploit. Since the vendor provided the fix and published a security advisory, the researchers decided to share the exploit code.
See also: Critical vulnerability in Node.js can cause server crashes

FortiSIEM: Which versions are affected – Fixes
The vulnerability affects FortiSIEM versions 6.7 to 7.5, and fixes are available in the following versions:
– FortiSIEM 7.4.1 or later
– FortiSIEM 7.3.5 or later
– FortiSIEM 7.2.7 or later
– FortiSIEM 7.1.9 or later
versions 7.0 and 6.7.0 are also affected but are no longer supported, so they will not receive a fix for CVE-2025-25256.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Fortinet clarified that this vulnerability does not affect FortiSIEM 7.5 and FortiSIEM Cloud versions.
See also: Serious bug in Broadcom software allows WiFi denial of service
The only alternative, for those who cannot apply the update immediately, is to restrict access to the phMonitor port (7900).
Horizon3.ai has also shared breach indicators that can help companies detect compromised systems. Looking at the logs for messages received from phMonitor (/opt/phoenix/log/phoenix.logs), the line with 'PHL_ERROR' should include the URL for the payload and the file it is written to.
Source: www.bleepingcomputer.com
