CVE-2025-25257
Fortinet FortiWeb SQL Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 August 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.77% probability · 100th percentile
- CISA KEV
- Listed 18 July 2025 · due 8 August 2025
- Weakness
- CWE-89
- Affected
- fortinet/fortiweb
- Source
- psirt@fortinet.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://fortiguard.fortinet.com/psirt/FG-IR-25-151 ; https://nvd.nist.gov/vuln/detail/CVE-2025-25257
References
- https://fortiguard.fortinet.com/psirt/FG-IR-25-151Vendor Advisory
- https://packetstorm.news/files/id/210193/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/52473Exploit, Third Party Advisory, VDB Entry
- https://github.com/0xbigshaq/CVE-2025-25257Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25257US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.