A critical vulnerability, CVE-2025-25256, has been identified in FortiSIEM, where an OS command injection flaw allows attackers to execute arbitrary system commands remotely. The flaw arises from insufficient input sanitization in command processing, which can lead to full system compromise and unauthorized access when exploited.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching according to the advisory. Potentially affected assets are detailed in this post.
References:

