CRITICAL

CVE-2025-25257

Fortinet Fortiweb 2025-07-17 CVSS v3.1
CVSS
9.8
KEV

Description

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Summary dbcve.org

SQL injection vulnerability in FortiWeb's web interface allows unauthenticated remote attackers to execute arbitrary SQL commands via specially crafted HTTP/HTTPS requests. The flaw exists in the parameter handling of specific API endpoints that fail to properly sanitize user input before incorporating it into SQL queries.

Mitigation

Apply Fortinet's available firmware updates for affected versions (7.6.4, 7.4.8, 7.2.11, 7.0.11 or later). Until patching is feasible, restrict network access to FortiWeb management interfaces to trusted IPs only via ACLs.

Proof of Concept

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

99.78%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE