
Detection artifact generator for FortiSIEM CVE-2025-25256 unauthenticated remote command execution vulnerability. Sends crafted packets to verify exploitability and aids in security assessment.
Detection Artifact Generator for FortiSIEM CVE-2025-25256
https://github.com/user-attachments/assets/1aa1040a-af34-460d-8844-1e440efa9ba1
See our blog post for technical details
python watchTowr-vs-FortiSIEM-CVE-2025-25256.py -r 192.168.8.232 -c whoami
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-FortiSIEM-CVE-2025-25256.py
(*) FortiSIEM Unauthenticated Remote Command Execution Detection Artifact Generator
- Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)
CVEs: [CVE-2025-25256]
[+] Packet Sent! ^-^
This script attempts to detect if FortiSIEM is vulnerable to CVE-2025-25256
The following versions of FortiSIEM are Affected
| Version | Affected | Solution |
|---|---|---|
| FortiSIEM 7.4 | Not affected | Not Applicable |
| FortiSIEM 7.3 | 7.3.0 through 7.3.1 | Upgrade to 7.3.2 or above |
| FortiSIEM 7.2 | 7.2.0 through 7.2.5 | Upgrade to 7.2.6 or above |
| FortiSIEM 7.1 | 7.1.0 through 7.1.7 | Upgrade to 7.1.8 or above |
| FortiSIEM 7.0 | 7.0.0 through 7.0.3 | Upgrade to 7.0.4 or above |
| FortiSIEM 6.7 | 6.7.0 through 6.7.9 | Upgrade to 6.7.10 or above |
| FortiSIEM 6.6 | 6.6 all versions | Migrate to a fixed release |
| FortiSIEM 6.5 | 6.5 all versions | Migrate to a fixed release |
| FortiSIEM 6.4 | 6.4 all versions | Migrate to a fixed release |
| FortiSIEM 6.3 | 6.3 all versions | Migrate to a fixed release |
| FortiSIEM 6.2 | 6.2 all versions | Migrate to a fixed release |
| FortiSIEM 6.1 | 6.1 all versions | Migrate to a fixed release |
| FortiSIEM 5.4 | 5.4 all versions | Migrate to a fixed release |
For more information visit FortiGuard Labs PSIRT
For the latest security research follow the watchTowr Labs Team