CVE-2025-47856: Fortinet Fortivoice
High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.
Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.
Affected products
- Fortinet Fortivoice: from 6.4.0, before 6.4.11 (fixed in 6.4.11); from 7.0.0, before 7.0.7 (fixed in 7.0.7); version 7.2.0 only
Published 2025-10-14. Last modified 2026-10-08.