logo

A Vulnerability in FortiWeb Could Allow for Remote Code Execution

ID: d5daa9ae-96d8-5ff4-81b6-8462943f30bb

STIX ID: report--d5daa9ae-96d8-5ff4-81b6-8462943f30bb

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2025-11-14

Date Updated: 2026-04-27

...
...

A relative path traversal vulnerability (CWE-23) in FortiWeb (CVE-2025-64446) may allow unauthenticated attackers to execute administrative commands and achieve remote code execution via crafted HTTP/HTTPS requests. The advisory maps the issue to Initial Access (Exploit Public-Facing Application, T1190) and notes that restricting the HTTP/HTTPS management interface to internal access reduces risk; the report does not state any observed active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.