CVE-2025-64153 | Fortinet FortiExtender up to 7.0.5/7.2.5/7.4.7/7.6.3 HTTP Request os command injection (FG-IR-25-739)
A vulnerability labeled as critical has been found in Fortinet FortiExtender up to 7.0.5/7.2.5/7.4.7/7.6.3. Impacted is an unknown function of the component HTTP Request Handler. Such manipulation leads to os command injection.
This vulnerability is referenced as CVE-2025-64153. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.