FortiWeb Vulnerabilities Exploited: Path Traversal and OS Command Injection
ID: 730b90d7-bcb9-5bb9-96d2-a6fe0a7b066f
STIX ID: report--730b90d7-bcb9-5bb9-96d2-a6fe0a7b066f
Feed Name: ThreatCluster
Two critical FortiWeb vulnerabilities are being actively exploited: an unauthenticated relative path traversal (CWE-23) allowing administrative command execution via crafted HTTP(S) requests, and an authenticated OS command injection (CWE-78) enabling attackers to run unauthorized code via HTTP requests or CLI commands. Fortinet advises disabling HTTP/HTTPS access on internet-facing interfaces as a temporary mitigation, reviewing configurations and logs for unauthorized changes, and performing upgrades; FortiAppSec Cloud is not affected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
