logo

Fortinet FortiWeb flaw CVE-2025-25257 exploited hours after PoC release

ID: f077fee2-43a7-57e1-959f-bbbe4d9a066d

STIX ID: report--f077fee2-43a7-57e1-959f-bbbe4d9a066d

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2025-07-19

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Fortinet FortiWeb CVE-2025-25257 (CVSS 9.6) is an unauthenticated SQL injection vulnerability that was exploited in the wild the same day a proof-of-concept was published; researchers demonstrated escalation to remote code execution via MySQL INTO OUTFILE and Python .pth files, Shadowserver observed dozens of compromises, and Fortinet released patches for multiple versions — administrators are urged to apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.