CVE-2025-47856: Fortinet Fortivoice

High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.

Affected products

  • Fortinet Fortivoice: from 6.4.0, before 6.4.11 (fixed in 6.4.11); from 7.0.0, before 7.0.7 (fixed in 7.0.7); version 7.2.0 only

Published 2025-10-14. Last modified 2026-10-08.