Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
proof-of-concept-releaserapid-weaponizationwidely-deployed-product-advisoryinternet-facing-service-vulnerability

FortiSIEM Unauthenticated RCE via phMonitor OS Command Injection (CVE-2025-64155)

Updated 3mo agoFirst seen Jan 14, 202613 sources

Fortinet disclosed and patched a critical FortiSIEM OS command injection vulnerability, CVE-2025-64155 (CVSS 9.4), that enables unauthenticated remote code execution via crafted TCP/CLI requests to the phMonitor service (default port 7900). Impact is reported on FortiSIEM Super and Worker nodes (Collector nodes reportedly not affected), with recommended upgrades to 7.4.1, 7.3.5, or 7.2.7; a key mitigation is to restrict network access to port 7900.

Technical analysis described an exploit chain in which attacker-controlled inputs in phMonitor requests can be leveraged for argument injection leading to arbitrary file write and code execution (initially as an admin-level context), followed by a file overwrite privilege escalation to root. Public exploit material is reported to be available, and the issue has drawn threat-actor interest (including references in leaked Black Basta chats), increasing the likelihood of opportunistic exploitation against exposed FortiSIEM deployments.

Share:
FortiSIEM Unauthenticated RCE via phMonitor OS Command Injection (CVE-2025-64155)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 15, 20265mo ago

Defused detects active exploitation of CVE-2025-64155 in honeypots

By 2026-01-15, Defused reported seeing targeted exploitation attempts against CVE-2025-64155 through honeypot deployments. The observed attacks followed public disclosure and PoC release, indicating the FortiSIEM flaw had moved from patch-only status to active abuse.

Jan 13, 20265mo ago

Horizon3.ai publishes technical analysis and PoC for CVE-2025-64155

On 2026-01-13, Horizon3.ai released a technical write-up and proof-of-concept exploit for CVE-2025-64155 after privately reporting the issue to Fortinet. The research described how unauthenticated argument injection in the phMonitor service could be used for arbitrary file write, admin-level code execution, and escalation to root, and included indicators of compromise and log-hunting guidance.

Fortinet releases advisory and patches for CVE-2025-64155 and other flaws

On 2026-01-13, Fortinet published advisory FG-IR-25-772 and released fixes for the critical FortiSIEM command injection flaw CVE-2025-64155, along with other vulnerabilities including the critical FortiFone Web Portal information disclosure bug CVE-2025-47855. Fortinet provided affected version details, upgrade guidance, and a workaround to restrict access to the phMonitor service on TCP port 7900.

Aug 1, 202511mo ago

Fortinet observes exploitation of CVE-2025-25256 in the wild

In August 2025, Fortinet issued an advisory for CVE-2025-25256, a FortiSIEM OS command injection flaw reachable via crafted CLI requests. The company said exploitation had been observed in the wild, and later research into this issue led to discovery of a related exploit chain tracked as CVE-2025-64155.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

48 LINKEDOpen in app
Threat actors
2 linked
Malware
2 linked
Affected products
3 linked
FortisiemFortiosFortiweb
Organizations
22 linked
FortinetHorizon3.aiDefusedTrend MicroCisco SystemsBleepingComputerD-LinkArctic WolfTenableThe Hacker NewsChina MobileTencenteSentireGitHubRedditContaboRescanaBaxet Group Inc.Secure-ISSChina Telecommunications CorporationSiamdata CommunicationSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.