Executive brief
FortiWeb is a web application firewall designed to protect corporate websites and applications from cyberattacks. A security flaw has been identified that could allow a person with administrative access to take full control of the device's underlying operating system. This could lead to a total compromise of the security appliance, potentially allowing attackers to intercept traffic or disrupt protected services.
Technical details
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability (CWE-78) exists in multiple versions of Fortinet FortiWeb. The flaw allows an authenticated attacker with high privileges to execute arbitrary commands on the underlying operating system. Exploitation can occur through specifically crafted HTTP requests or via the Command Line Interface (CLI). This vulnerability has been observed being exploited in the wild and is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Users are advised to upgrade to FortiWeb versions 7.0.12, 7.2.12, 7.4.11, 7.6.6, or 8.0.2 and later.
Affected products
- Fortinet FortiWeb 8.0.0 through 8.0.1, 7.6.0 through 7.6.5, 7.4.0 through 7.4.10, 7.2.0 through 7.2.11, 7.0.0 through 7.0.11
Timeline
- 2025-11-18: disclosed
- 2025-11-18: advisory
- 2025-11-18: kev added: Added to CISA KEV catalog due to active exploitation.