The Register Home Page

back to article Fortinet discloses critical bug with working exploit code amid surge in brute-force attempts

Fortinet warned customers about a critical FortiSIEM bug that could allow an unauthenticated attacker to execute unauthorized commands, and said working exploit code for the flaw has been found in the wild. The OS-command-injection vulnerability, tracked as CVE-2025-25256, received a 9.8 CVSS rating and affects multiple …

  1. elDog Silver badge

    Fortinet? The security company? Again?

    Is there a contest with some other huge software vendor to see who can have the most 9.0+ CVEs in a reporting period?

    I'm not implying Adobe or Microsoft or anyone else is part of this group!

    Perhaps someone could share Fortinet's "best practices" for software security design. That would help the rest of us to know what not to do.

    1. Anonymous Coward
      Anonymous Coward

      Re: Fortinet? The security company? Again? .... again !!!

      I think the problem is far too many of these 'Software Vendors' etc are using the wrong 'Practise/Practice' ..... and never get near to the 'makes perfect' stage !!!

      :)

    2. sanmigueelbeer
      Coat

      Re: Fortinet? The security company? Again?

      Some big company is going to "lobby" TACO to cut (or withdraw) funding to MITRE permanently.

      No MITRE no CVE scores, no one cares (to fix). Mo money! Win-Win!

      1. Anonymous Coward
        Anonymous Coward

        Re: Fortinet? The security company? Again?

        I find this whole TACO thing very insulting..

        .. to Mexican food.

    3. GNU Enjoyer
      Angel

      Re: Fortinet? The security company? Again?

      That's quite easy - just poorly program proprietary software and decline to fix bugs.

      CVEs are primarily only useful for embarrassing proprietary software developers into fixing critical vulnerabilities, as otherwise they leave em (although it seems that some companies have taken to filings CVEs for each bug, rather than properly documenting the bugfixes in the version changelog (wait, no changelog?)).

  2. HMcG

    The whole problem comes down to the exemption of software from the normal legal obligation to make a product fit for service. That was accepted when we had a small and burgeoning tech industy. where being made responible for customer losses due to negligent programming would bankrupt the industry. It's not accepatable now that those tech companies have grown to be the largest in the world. If the car industry had been allowed off scot-free for selling faulty and dangerous vechicles due to negligent, or roads would be carnage on a monumental scale.

    It's time to make companies like Microsoft et al responible for customer losses where the software is cleary unfit for purpose, and demonstrably so. Yes, that will cost the software industry billions upon billions, but it's the only way that the situation will ever improve.

    1. Claptrap314 Silver badge

      The food industry, especially the breakfast sector is just as bad.

      Don't look too closely, because it's happening in medicine.

      Need I mention the 787 SuperMax?

      I agree that software companies should be held criminally negligent. But I'm hard-pressed to think of standards that could be enforced.

      1. druck Silver badge

        737 Max?

  3. pc-fluesterer.info
    Stop

    Backdoor?

    "improper neutralization of special elements used in an OS command"

    Just saying.

    The who knows the key opens the door.

  4. wzis

    They should use WZIS Software's software to protect them.

    WZIS Software Pty Ltd's security software is the only one that can help users to run 3rd party security commands to combat software based attacks, such as strace, dtrace, systemtap, bpftrace, uprobe, kprobe, ftrace, memory snoopers.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like