U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalog
ID: e30f87f5-2d6f-5cb3-9709-8b13e4658539
STIX ID: report--e30f87f5-2d6f-5cb3-9709-8b13e4658539
Feed Name: Security Affairs
CISA added Fortinet FortiWeb CVE-2025-64446 (CVSS 9.1) to its Known Exploited Vulnerabilities catalog after active exploitation was observed; the flaw is a relative path traversal in multiple FortiWeb versions that permits unauthenticated attackers to execute administrative commands and create admin accounts via crafted HTTP POST requests (notably to /api/v2.0/cmdb/system/admin%3F/../../../../../cgi-bin/fwbcgi). PoCs and an exploitation tool have been published, payloads containing created credentials were observed, Fortinet released fixes (e.g., 8.0.2), and CISA ordered agencies to remediate by November 21, 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
