October 2025 brought a sharp reminder that network edge devices remain high-value targets. Fortinet published 29 security advisories covering more than 30 vulnerabilities across its product portfolio, including a high-severity flaw in FortiOS that affects dozens of hardware models deployed in enterprise environments worldwide. At the same time, CISA continued expanding its Known Exploited Vulnerabilities catalog, adding entries that demand immediate patching attention from federal agencies and private-sector organizations alike.

These disclosures follow a pattern that has intensified throughout 2025: threat actors are systematically targeting network perimeter appliances because they sit at trust boundaries, often run with elevated privileges, and frequently lag behind on patch cycles due to change-management complexity.

FortiOS CLI Command Bypass (CVE-2025-58325)

On October 14, 2025, Fortinet released advisory FG-IR-24-361 addressing CVE-2025-58325, a high-severity vulnerability (CVSS 7.8) classified as “Incorrect Provision of Specified Functionality.” The flaw allows a local authenticated attacker to execute arbitrary system commands via crafted CLI commands, bypassing restricted command protections.

Advertisement

CyberTech Your brand belongs here. Reach the decision-makers who read CyberTech every day. Premium placements across the site and newsletter. Advertise with us

Affected versions span FortiOS 6.4, FortiOS 7.0.0 through 7.0.15, FortiOS 7.2.0 through 7.2.10, FortiOS 7.4.0 through 7.4.5, and FortiOS 7.6.0. The vulnerability impacts a broad range of hardware platforms, including models 100E through 7000F series, covering small branch offices through data center deployments. CERT-EU issued a corresponding advisory (2025-039) classifying the risk as high severity.

Defenders running affected FortiOS versions should upgrade immediately. The breadth of affected platforms means that organizations with mixed hardware generations face a complex patching matrix, potentially requiring firmware upgrades on dozens of distinct appliance models.

CISA Expands Known Exploited Vulnerabilities Catalog

CISA added five new entries to its Known Exploited Vulnerabilities (KEV) catalog on October 14, 2025, including CVE-2025-24990 (a Microsoft Windows Untrusted Pointer Dereference vulnerability) and CVE-2025-59230 (a Microsoft Windows Improper Access Control vulnerability). Federal civilian agencies face binding operational directives to remediate KEV entries within specified timelines, but private-sector defenders should treat KEV additions as high-confidence indicators of active exploitation.

By December 2025, CISA had added additional entries including three on December 17 and one on December 29, maintaining its cadence of flagging vulnerabilities where exploitation evidence exists in the wild. The catalog serves as a prioritization mechanism for patch management teams drowning in monthly disclosure volumes that routinely exceed 2,000 CVEs.

The Edge Device Problem

Fortinet’s disclosure follows a pattern visible across the entire network appliance market in 2025. Edge devices including firewalls, VPN concentrators, and load balancers present attackers with several advantages: they process traffic from untrusted networks, they often run proprietary operating systems with limited security tooling, and their patch cycles are slower than cloud-hosted software because downtime requires change windows.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

For security teams, the mitigation strategy has three layers. First, reduce attack surface by disabling management interfaces accessible from the internet. Second, implement virtual patching through WAF or IPS rules while scheduling firmware upgrades. Third, monitor for post-exploitation indicators, particularly unusual CLI activity or configuration changes that could indicate an attacker leveraging a command execution vulnerability.

Prioritization Framework

The combination of CISA KEV entries and vendor PSIRT advisories gives defenders a two-signal prioritization model. When a CVE appears in both the vendor advisory and the KEV catalog, it confirms active exploitation and should receive emergency patching priority regardless of CVSS score alone. When a vendor advisory rates a flaw as high severity but no KEV entry exists, risk-based prioritization should consider the accessibility of the vulnerable component (internet-facing versus internal) and the privilege level required for exploitation.

October 2025 demonstrated that edge device security remains a persistent challenge. Organizations that treat perimeter appliance patching as routine maintenance rather than critical security hygiene continue to provide adversaries with reliable initial-access vectors.

Related: Fortinet Launches FortiOS 8.0 at Accelerate 2026