CVE-2025-58034
Description
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.
Summary dbcve.org
FortiWeb versions 7.0.0-7.0.11, 7.2.0-7.2.11, 7.4.0-7.4.10, 7.6.0-7.6.5, and 8.0.0-8.0.1 contain an OS Command Injection (CWE-78) vulnerability allowing authenticated attackers to execute arbitrary code on the underlying system via crafted HTTP requests or CLI commands. The vulnerability requires authentication but can be exploited remotely through the web management interface.
Mitigation
Upgrade FortiWeb to the latest patched version available from Fortinet's security advisory. As an interim control, restrict access to the FortiWeb management interface to trusted IP addresses only and disable unnecessary management access paths.