logo

Unauthenticated Authentication Bypass in Fortinet FortiWeb (CVE-2025-64446) Exploited in the Wild

ID: c31ddcbc-2312-591b-898b-52e8aa0e9bb0

STIX ID: report--c31ddcbc-2312-591b-898b-52e8aa0e9bb0

Feed Name: Qualys Blog

Threat Score
90/100

Date Published: 2025-11-15

Date Updated: 2026-04-28

Author: Mayuresh Dani

...
...

### Executive Summary: A critical authentication bypass (CVE-2025-64446, CVSS 9.8) in Fortinet FortiWeb is being actively exploited since early October 2025; attackers chain a path traversal to reach the fwbcgi CGI and supply a base64-encoded CGIINFO header that impersonates the built-in admin to create persistent administrative accounts. The advisory lists affected FortiWeb versions, Qualys QIDs for detection, network- and host-based IOCs, and remediation guidance (upgrade to specified fixed versions or temporarily disable HTTP/HTTPS).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.