CVE-2025-58692
8.8Fortinet · FortiVoice
An SQL injection vulnerability in Fortinet FortiVoice allows authenticated attackers to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
Executive summary
A critical SQL injection vulnerability in Fortinet FortiVoice allows authenticated attackers to execute arbitrary code or commands, posing a significant risk of total system compromise.
Vulnerability
This is an improper neutralization of special elements used in an SQL command (CWE-89) that permits an authenticated attacker to manipulate backend database queries. By sending specifically crafted HTTP or HTTPS requests, the attacker can achieve unauthorized code execution.
Business impact
The ability to execute unauthorized code or commands on a critical voice communication appliance presents a severe risk to organizational operations. A successful exploit could lead to complete system takeover, unauthorized access to sensitive voice data, or the potential for lateral movement within the network. Given the CVSS score of 8.8, this vulnerability is considered a high-priority threat that requires immediate remediation.
Remediation
Immediate Action: Upgrade FortiVoice to version 7.2.3 or 7.0.8 or higher to resolve the underlying SQL injection flaw.
Proactive Monitoring: Review web server and database access logs for anomalous SQL syntax or unexpected query patterns originating from authenticated user accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to detect and block malicious SQL injection patterns targeting the FortiVoice interface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing affected versions of Fortinet FortiVoice must prioritize upgrading to the patched versions immediately. Because this vulnerability grants authenticated users the capability to execute arbitrary code, patching is the only effective way to prevent potential exploitation. Verify that all administrative access to the management interface is restricted to authorized personnel while the update process is underway.