OS Command Injection Vulnerability in Fortinet FortiVoice
CVE-2025-47856
7.2HIGH
What is CVE-2025-47856?
This vulnerability in Fortinet FortiVoice allows attackers with privileged access to exploit improper neutralization of special elements in OS commands. By crafting specific HTTP or HTTPS requests or using CLI commands, an attacker can execute arbitrary code on affected versions. This vulnerability poses a significant risk by potentially allowing unauthorized control over the affected system, which may lead to data breaches or service disruption.
Affected Version(s)
FortiVoice 7.2.0
FortiVoice 7.0.0 <= 7.0.6
FortiVoice 6.4.0 <= 6.4.10