CVE-2025-64153

Source
https://cve.org/CVERecord?id=CVE-2025-64153
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64153.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-64153
Published
2025-12-09T18:16:04.910Z
Modified
2026-03-13T03:38:22.114354Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "7.0.0"
            },
            {
                "last_affected": "7.0.4"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.2.0"
            },
            {
                "last_affected": "7.2.5"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.4.0"
            },
            {
                "last_affected": "7.4.7"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.6.0"
            },
            {
                "last_affected": "7.6.3"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64153.json"