SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-25257

Fortinet FortiWeb SQL Injection Vulnerability

KEVCRITICAL 9.8EPSS 99.8%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 August 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.77% probability · 100th percentile
CISA KEV
Listed 18 July 2025 · due 8 August 2025
Weakness
CWE-89
Affected
fortinet/fortiweb
Source
psirt@fortinet.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://fortiguard.fortinet.com/psirt/FG-IR-25-151 ; https://nvd.nist.gov/vuln/detail/CVE-2025-25257

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.