FortiWeb Authentication Bypass Vulnerability Allows Logins as Any Existing User
ID: 010f8a86-c057-5846-989c-8ca45b0776ec
STIX ID: report--010f8a86-c057-5846-989c-8ca45b0776ec
Feed Name: GBHackers
Fortinet FortiWeb contains a high-severity authentication-bypass vulnerability (CVE-2025-52970, "Fort-Majeure") in its cookie parsing (the Era parameter) that can trigger an out-of-bounds read and cause the server to use predictable all-zero session keys, enabling attacker impersonation including administrative users; Fortinet published an advisory and released patches for affected 7.x releases on August 12, 2025, and organisations should prioritise upgrading, though exploitation requires brute-forcing a validation number and active user sessions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
