Executive brief
Fortinet FortiWeb is a web application firewall designed to protect corporate websites and applications from cyberattacks. A critical vulnerability has been identified that allows an unauthorized person to bypass security controls and run administrative commands on the device. This could lead to a complete takeover of the security appliance, potentially exposing sensitive data or allowing attackers to disable network protections. This vulnerability is currently being exploited in the wild.
Technical details
A relative path traversal vulnerability (CWE-23) exists in multiple versions of Fortinet FortiWeb. The flaw allows a remote, unauthenticated attacker to send specially crafted HTTP or HTTPS requests to the management interface or affected service. By manipulating file paths in these requests, the attacker can bypass intended restrictions to execute arbitrary administrative commands on the underlying operating system. This vulnerability has a CVSS 3.1 score of 9.8 and is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Users should update to FortiWeb versions 8.0.2, 7.6.5, 7.4.10, 7.2.12, or 7.0.12 as applicable.
Affected products
- Fortinet FortiWeb 8.0.0 through 8.0.1, 7.6.0 through 7.6.4, 7.4.0 through 7.4.9, 7.2.0 through 7.2.11, 7.0.0 through 7.0.11
Timeline
- 2025-11-14: disclosed: Initial disclosure by Fortinet
- 2025-11-14: advisory: Fortinet PSIRT FG-IR-25-910 published
- 2025-11-14: kev added: CISA added to Known Exploited Vulnerabilities catalog
- 2025-11-14: exploited: Confirmed active exploitation in the wild