OS Command Injection Vulnerability in FortiADC Products from Fortinet
CVE-2025-31104
7HIGH
What is CVE-2025-31104?
An OS Command Injection vulnerability in FortiADC allows authenticated attackers to execute unauthorized commands through specially crafted HTTP requests. Affected versions include FortiADC 7.6.0 to 7.6.1, 7.4.0 to 7.4.6, 7.2.0 to 7.2.7, 7.1.0 to 7.1.4, and all versions of 7.0, 6.2, and 6.1. This flaw could lead to severe security breaches if exploited, enabling attackers to manipulate server processes maliciously.
Affected Version(s)
FortiADC 7.6.0 <= 7.6.1
FortiADC 7.4.0 <= 7.4.6
FortiADC 7.2.0 <= 7.2.7