CRITICAL

CVE-2025-64446

Fortinet Fortiweb 2025-11-14 CVSS v3.1
CVSS
9.8
KEV

Description

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Summary dbcve.org

A relative path traversal vulnerability in FortiWeb allows attackers to use '../' sequences in HTTP/HTTPS requests to navigate outside the web root and execute arbitrary administrative commands on the system. This is a pre-authentication flaw enabling remote code execution with administrative privileges.

Mitigation

Apply vendor-supplied patches to upgrade FortiWeb to the latest version; restrict access to the management interface to trusted networks only until patching is possible.

Proof of Concept

Weakness (CWE)

CWE-23

EPSS Score

91.84%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE