Command injection vulnerability

Summary

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in FortiVoice may allow a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests.

Version Affected Solution
FortiVoice 7.2 7.2.0 Upgrade to 7.2.1 or above
FortiVoice 7.0 7.0.0 through 7.0.6 Upgrade to 7.0.7 or above
FortiVoice 6.4 6.4.0 through 6.4.10 Upgrade to 6.4.11 or above

Timeline

2025-07-08: Initial publication