Fortinet released a security advisory on October 14, 2025, addressing a high severity vulnerability in its FortiOS product, identified as CVE-2025-58325. This vulnerability, which has a CVSS score of 7.8, is classified as an Incorrect Provision of Specified Functionality flow. It allows a local authenticated attacker to execute system commands by leveraging crafted CLI commands, potentially leading to unauthorized control over affected devices. The vulnerability impacts several versions of FortiOS, specifically versions 6.4, 7.0.0 through 7.0.15, 7.2.0 through 7.2.10, 7.4.0 through 7.4.5, and 7.6.0. Affected hardware platforms include a wide range of Fortinet devices such as the 100E/101E, 100F/101F, 1100E/1101E, 1800F/1801F, 2200E/2201E, 2600F/2601F, 3300E/3301E, 3400E/3401E, 3500F/3501F, 3600E/3601E, 3800D, 3960E, 3980E, 4200F/4201F, 4400F/4401F, 5001E, 6000F, 7000E, and 7000F. Other models are not affected by this vulnerability. The vulnerability requires local authentication, which means an attacker must already have access to the device to exploit it, but successful exploitation could allow for full system command execution. Fortinet strongly recommends that all users and administrators of affected products update to the latest versions to mitigate the risk. The advisory was published in coordination with security organizations, and users are urged to consult the official Fortinet PSIRT advisory for detailed mitigation steps. The Canadian Centre for Cyber Security also issued an alert encouraging prompt review and application of the necessary updates. No reports of active exploitation in the wild have been confirmed at the time of the advisory's release. The vulnerability does not affect all Fortinet models, so organizations should carefully review the list of impacted devices. The advisory highlights the importance of maintaining up-to-date firmware and monitoring for unusual activity on Fortinet devices. Organizations are advised to follow best practices for access control and to restrict local access to trusted personnel only. The release of this advisory underscores the ongoing need for vigilance in managing network security appliances. Fortinet has provided detailed guidance and links to patches to assist organizations in remediation. Security teams should prioritize patching affected FortiOS versions to prevent potential compromise. The incident serves as a reminder of the risks posed by local privilege escalation vulnerabilities in critical network infrastructure.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
CERT-EU published Security Advisory 2025-039 warning of a high-severity vulnerability in FortiOS. The reference does not include further details on exploitation, patching, or affected organizations.
The Canadian Centre for Cyber Security published advisory AV25-668 regarding a Fortinet security issue. No additional technical details or remediation timeline are provided in the reference.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.