CVE-2025-52970
78Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 7.7epss 9.8%
from disclosure to weapon26 days
Published on NVDAug 12
1st PoC+26d
VulnCheck+23d
exploitation probability
9.8%top 5% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:C
Affected products
Fortinet · FortiWebpublic PoCs found — 2
vulncheckvulncheck.com/xdb/6d2494a00260unverifiedvulncheckvulncheck.com/xdb/ac25fe9ad70cunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.