FortiWeb Vulnerabilities Exploited: Path Traversal and OS Command Injection
ID: 4e4b5f5d-d593-5dea-8bf1-6312d2bf3e26
STIX ID: report--4e4b5f5d-d593-5dea-8bf1-6312d2bf3e26
Feed Name: ThreatCluster
Two critical FortiWeb vulnerabilities are actively being exploited: an unauthenticated relative path traversal (CWE-23) that can execute administrative commands via crafted HTTP/HTTPS requests, and an authenticated OS command injection (CWE-78) that enables execution of unauthorized code via crafted requests or CLI commands; FortiWeb systems are affected (FortiAppSec Cloud is not). Fortinet recommends disabling HTTP/HTTPS on internet-facing interfaces as a temporary mitigation and reviewing configurations and logs for unauthorized changes while upgrades are applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
