
[CIVN-2025-0321] Path Traversal Vulnerability in Fortinet FortiWeb
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Path Traversal Vulnerability in Fortinet FortiWeb
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
FortiWeb version 7.0.0 to 7.0.11
FortiWeb version 7.2.0 to 7.2.11
FortiWeb version 7.4.0 to 7.4.9
FortiWeb version 7.6.0 to 7.6.4
FortiWeb version 8.0.0 to 8.0.1
Overview
A vulnerability has been reported in Fortinet FortiWeb web application firewalls which could allow an unauthenticated attacker to execute administrative commands on the targeted system.
Target Audience:
Organizations and individuals using the affected Fortinet FortiWeb versions.
Risk Assessment:
High risk of authentication bypass and system compromise.
Impact Assessment:
Potential for complete account takeover and data exfiltration.
Description
Fortinet FortiWeb is a web application firewall (WAF) designed to protect web applications from a wide range of security threats, such as SQL injection, cross-site scripting (XSS), and other web-based attacks.
This vulnerability exists in Fortinet FortiWeb web application firewalls due to an input validation error when processing directory traversal sequences. This flaw allows an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
Successful exploitation of this vulnerability could allow an attacker to create admin accounts and gain complete control over vulnerable devices exposed to the internet.
Note: This vulnerability (CVE 2025 64446) is being exploited in the wild. Users are advised to apply patches urgently.
Solution
Apply appropriate software updates as mentioned by the vendor:
https://fortiguard.fortinet.com/psirt/FG-IR-25-910
Vendor Information
Fortinet
https://fortiguard.fortinet.com/psirt/FG-IR-25-910
References
Fortinet
https://fortiguard.fortinet.com/psirt/FG-IR-25-910
CVE Name
CVE-2025-64446
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmkciCkACgkQ3jCgcSdc
ys8Wzg//dIdUqlEWaGcP5Nxh9seh9LwnfH4mNcYZX3iTfoq12Q3ZzKEoLIY+NX8A
EgnyspzjCCVWwDdvZBQHDAsSRtNWahLCNGrz2G34SzjajpwEM3ryg9pxsTQrmGwb
G6JTzuiIcl6pKkJ2D+ksXjjMM+anwLeN8wo7ajoqrjDHnScUruUekxCOp+eJG1I1
JShimhPiiAbxDeOAUa/kBlwIkXK9wL8NLApc8YFwSo1vxcWI9+ELujiijLrgqSi4
dKb35og0FRDY+w3DZ+paji7lXrr+g42i9yncjCvTU9o6jIqb8mg2wtnKLxhizb/i
LO8r2RM9hxmGn+D3LdRItSYDWfDM0wgIA42wGFTSBUgyJm/L5m9q39+pFYJ+p6sb
6FihsP1S1SXrQt52CoGJZROhMBMqDzkicN6kAu994FuOuEzxx09ZcPBaq6tShX4v
TkQjw+LXvFuTbzMHEuV7rGF9c7xoyx5yZU3OEXun5KHgGL7XvfdbMz/MEHDtBKzy
5jmnSjg5mg6DMzFvT7wpBGSJmPJcKw7Yu/ZwqUcHICxSCLY98KB0+xbGDoDS/cHD
++aTPZsLi2d2lP6xQBhP0SIXBOqaRyLaBgd4DEu/A4WnC/a/rzCKetW82EuIemyq
BnCvQZn0NZwHZgDmCuZj8N15zCBVdQHNQw/3dyCSNSwXRjq5plg=
=5xm5
—–END PGP SIGNATURE—–


