HIGH

CVE-2025-58034

Fortinet Fortiweb 2025-11-18 CVSS v3.1
CVSS
7.2
KEV

Description

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

Summary dbcve.org

FortiWeb versions 7.0.0-7.0.11, 7.2.0-7.2.11, 7.4.0-7.4.10, 7.6.0-7.6.5, and 8.0.0-8.0.1 contain an OS Command Injection (CWE-78) vulnerability allowing authenticated attackers to execute arbitrary code on the underlying system via crafted HTTP requests or CLI commands. The vulnerability requires authentication but can be exploited remotely through the web management interface.

Mitigation

Upgrade FortiWeb to the latest patched version available from Fortinet's security advisory. As an interim control, restrict access to the FortiWeb management interface to trusted IP addresses only and disable unnecessary management access paths.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

55.58%
Probability of exploitation in next 30 days
99th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE