Executive brief
FortiWeb is a web application firewall designed to protect corporate websites and applications from cyberattacks. A critical vulnerability has been identified that allows unauthorized individuals to run malicious database commands by sending specially crafted web traffic. This could lead to the theft of sensitive customer data, unauthorized modification of records, or a complete takeover of the security appliance. This vulnerability is reportedly being exploited in the wild.
Technical details
A SQL injection vulnerability (CWE-89) exists in Fortinet FortiWeb due to improper neutralization of special elements used in SQL commands. The flaw can be triggered by an unauthenticated remote attacker sending specially crafted HTTP or HTTPS requests to the appliance. Successful exploitation allows the attacker to execute arbitrary SQL commands, potentially leading to full database compromise, data exfiltration, or administrative bypass. The vulnerability affects multiple major versions including 7.0, 7.2, 7.4, and 7.6. This flaw is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation.
Affected products
- Fortinet FortiWeb 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10
Timeline
- 2025-07-17: disclosed: Initial disclosure by Fortinet
- 2025-07-18: advisory: NVD publication and CISA KEV addition
- 2025-07-18: exploited: Added to CISA KEV catalog due to active exploitation