Junglewise Threat Intelligence

CVE-2025-67862: Fortinet FortiOS and FortiProxy Lua script execution in CLI

CVE-2025-67862 · Severity: medium · CVSS 6.7 · Published 2026-06-09

Technologies: Fortinet FortiOS, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

A vulnerability in Fortinet's networking and proxy software could allow an administrator with existing access to bypass security restrictions. By using specific commands, an authorized user could run unauthorized scripts on the system. This could lead to a full compromise of the device, potentially impacting the security of the entire network it manages.

Technical details

This vulnerability (CWE-1244) exists in the Command Line Interface (CLI) of FortiOS and FortiProxy. It stems from an internal asset being exposed to an unsafe debug access level, which allows an authenticated administrator to escape the restricted CLI environment. By providing specially crafted CLI commands, an attacker with high privileges can execute arbitrary Lua scripts on the underlying system. This can lead to a complete loss of confidentiality, integrity, and availability. Patches are available in FortiOS versions 7.6.3, 7.4.8, 7.2.11 and FortiProxy versions 7.6.4, 7.4.11, 7.2.15.

Affected products

  • Fortinet FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions
  • Fortinet FortiProxy 7.6.0 through 7.6.3, 7.4.0 through 7.4.10, 7.2.0 through 7.2.14, 7.0 all versions

Timeline

  • 2026-06-09: disclosed: Initial publication of the advisory by Fortinet.
  • 2026-06-09: advisory: NVD published the CVE record.

References

Related threats