A high-severity SQL injection vulnerability, tracked as CVE-2025-58692, was discovered in Fortinet FortiVoice, a Voice-over-IP (VoIP) solution used by enterprises. The flaw affects FortiVoice versions 7.0.0 through 7.0.7 and 7.2.0 through 7.2.2, allowing remote, authenticated attackers to inject arbitrary SQL statements via specially crafted HTTP or HTTPS requests. Successful exploitation could result in arbitrary code execution, potentially leading to full system compromise. Fortinet has released patches, recommending users upgrade to FortiVoice 7.0.8 or newer and 7.2.3 or newer to mitigate the risk.
Security advisories and vulnerability databases have highlighted the critical nature of this issue, assigning it a CVSS score of 8.8. Organizations are urged to identify and update vulnerable FortiVoice installations promptly. Tools and queries are available to help administrators locate at-risk systems within their networks. No evidence of active exploitation has been reported as of the latest advisories, but the potential impact underscores the importance of immediate remediation.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
runZero published a blog post explaining how defenders can find Fortinet FortiVoice installations on their networks. The post represents a defensive response aimed at helping organizations assess exposure after the vulnerability disclosure.
A high-severity CVE entry for CVE-2025-58692 was published, identifying a Fortinet FortiVoice SQL injection vulnerability. The CVE publication formalized public tracking of at least one of the disclosed flaws.
Fortinet published advisory FG-IR-25-666 describing SQL injection vulnerabilities affecting the voice and administrative interfaces in FortiVoice. This appears to be the initial public disclosure of the issue set.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
fortiguard.fortinet.com
Open sourcerunzero.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.