Fortinet FortiWeb flaw CVE-2025-25257 exploited hours after PoC release
ID: f077fee2-43a7-57e1-959f-bbbe4d9a066d
STIX ID: report--f077fee2-43a7-57e1-959f-bbbe4d9a066d
Feed Name: Security Affairs
Threat Score
Fortinet FortiWeb CVE-2025-25257 (CVSS 9.6) is an unauthenticated SQL injection vulnerability that was exploited in the wild the same day a proof-of-concept was published; researchers demonstrated escalation to remote code execution via MySQL INTO OUTFILE and Python .pth files, Shadowserver observed dozens of compromises, and Fortinet released patches for multiple versions — administrators are urged to apply updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
