CVE-2025-25257: critical vulnerability in Fortinet FortiWeb
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
FortiWeb versions 7.0 through 7.6 contain a SQL injection vulnerability that allows attackers to execute arbitrary SQL commands without authentication. This is critical because an attacker could access, modify, or delete sensitive database information.
SQL injection vulnerability in FortiWeb allows unauthenticated attackers to inject malicious SQL code through crafted HTTP/HTTPS requests due to improper input neutralization. Affected versions include 7.0.0-7.0.10, 7.2.0-7.2.10, 7.4.0-7.4.7, and 7.6.0-7.6.3. Successful exploitation enables unauthorized database access and manipulation with CVSS 9.6 criticality.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.