Medium severity6.7NVD Advisory· Published Apr 8, 2025· Updated Jun 17, 2026
CVE-2024-54025
CVE-2024-54025
Description
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator CLI before version 2.4.6 allows a privileged attacker to execute unauthorized code or commands via crafted CLI requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:fortinet:fortiisolator:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortiisolator:*:*:*:*:*:*:*:*range: >=2.4.3,<2.4.7
- (no CPE)range: <2.4.6
- (no CPE)range: 2.4.3
Patches
Vulnerability mechanics
References
1- fortiguard.fortinet.com/psirt/FG-IR-24-392nvdVendor Advisory
News mentions
0No linked articles in our index yet.