SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-52970

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device…

HIGH 8.1EPSS 9.75%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (9.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
9.75% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-233
Affected
fortinet/fortiweb
Source
psirt@fortinet.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.