CVE-2025-25257criticalunder attackCWE-89

CVE-2025-25257: critical vulnerability in Fortinet FortiWeb

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.6epss 100%
from disclosure to weapon0 days
Published on NVDJul 17
1st PoCJul 10
CISA KEV+1d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
25 public exploit(s)
Action required by CISAfederal deadline: 2025-08-08

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

FortiWeb versions 7.0 through 7.6 contain a SQL injection vulnerability that allows attackers to execute arbitrary SQL commands without authentication. This is critical because an attacker could access, modify, or delete sensitive database information.

Technical detail

SQL injection vulnerability in FortiWeb allows unauthenticated attackers to inject malicious SQL code through crafted HTTP/HTTPS requests due to improper input neutralization. Affected versions include 7.0.0-7.0.10, 7.2.0-7.2.10, 7.4.0-7.4.7, and 7.6.0-7.6.3. Successful exploitation enables unauthorized database access and manipulation with CVSS 9.6 criticality.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C
Affected products
Fortinet · FortiWeb
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.