Restricted CLI command bypass

Summary

An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS may allow a local authenticated attacker to execute system commands via crafted CLI commands.

Version Affected Solution
FortiOS 7.6 7.6.0 Upgrade to 7.6.1 or above
FortiOS 7.4 7.4.0 through 7.4.5 Upgrade to 7.4.6 or above
FortiOS 7.2 7.2.0 through 7.2.10 Upgrade to 7.2.11 or above
FortiOS 7.0 7.0.0 through 7.0.15 Upgrade to 7.0.16 or above
FortiOS 6.4 6.4 all versions Migrate to a fixed release
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

Impacted platforms:

100E/101E, 100F/101F, 1100E/1101E, 1800F/1801F, 2200E/2201E, 2600F/2601F, 3300E/3301E, 3400E/3401E, 3500F/3501F, 3600E/3601E, 3800D, 3960E, 3980E, 4200F/4201F, 4400F/4401F, 5001E, 6000F, 7000E, 7000F

Other models are not affected by this vulnerability.

Acknowledgement

Internally discovered and reported by Francois Ropert of Fortinet PSIRT team.

Timeline

2025-10-14: Initial publication