Unauthenticated Authentication Bypass in Fortinet FortiWeb (CVE-2025-64446) Exploited in the Wild
ID: c31ddcbc-2312-591b-898b-52e8aa0e9bb0
STIX ID: report--c31ddcbc-2312-591b-898b-52e8aa0e9bb0
Feed Name: Qualys Blog
### Executive Summary: A critical authentication bypass (CVE-2025-64446, CVSS 9.8) in Fortinet FortiWeb is being actively exploited since early October 2025; attackers chain a path traversal to reach the fwbcgi CGI and supply a base64-encoded CGIINFO header that impersonates the built-in admin to create persistent administrative accounts. The advisory lists affected FortiWeb versions, Qualys QIDs for detection, network- and host-based IOCs, and remediation guidance (upgrade to specified fixed versions or temporarily disable HTTP/HTTPS).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
