Fortinet FortiVoice OS Command Injection Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability allowing OS command injection has been identified in Fortinet FortiVoice versions 7.2.0, 7.0.0 through 7.0.6, and prior to 6.4.10. This vulnerability arises from improper neutralization of special elements used in OS commands, and it allows a privileged attacker to execute arbitrary code or commands. The exploitation can be carried out via crafted HTTP, HTTPS, or CLI requests.

Impact

Exploitation of this vulnerability allows for unauthorized execution of code or commands on the affected system.

Remediation

Users can upgrade to Fortinet FortiVoice 7.2.1 or above, 7.0.7 or above, or 6.4.11 or above, depending on their current version.

Added: Oct 14, 2025, 2:17 PM
Updated: Oct 14, 2025, 11:28 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.