CVE-2025-64446
Description
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
Summary dbcve.org
A relative path traversal vulnerability in FortiWeb allows attackers to use '../' sequences in HTTP/HTTPS requests to navigate outside the web root and execute arbitrary administrative commands on the system. This is a pre-authentication flaw enabling remote code execution with administrative privileges.
Mitigation
Apply vendor-supplied patches to upgrade FortiWeb to the latest version; restrict access to the management interface to trusted networks only until patching is possible.