Remote Code Execution Vulnerability in Fortinet FortiOS and FortiProxy
CVE-2023-25610
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 24 March 2025
What is CVE-2023-25610?
A critical buffer underwrite vulnerability in the administrative interface of Fortinet's FortiOS and FortiProxy allows remote unauthenticated attackers to potentially execute arbitrary code or commands. This vulnerability affects several versions across FortiOS and FortiProxy products, providing a vector for hidden exploits if successfully targeted. Organizations using the affected software are advised to take immediate action to secure their systems against potential attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FortiAnalyzer 7.2.0
FortiAnalyzer 7.0.0 <= 7.0.4
FortiAnalyzer 6.4.0 <= 6.4.11
References
EPSS Score
25% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved