logo

FortiWeb CVE-2025-64446 Vulnerability: Path Traversal Leads to Remote Code Execution

ID: e3a65c67-2173-5ddb-9997-d1a02afa09e1

STIX ID: report--e3a65c67-2173-5ddb-9997-d1a02afa09e1

Feed Name: Resources-2

Threat Score
90/100

Date Published: 2025-11-17

Date Updated: 2026-07-22

Author: Huseyin Can YUCEEL

...
...

**FortiWeb CVE-2025-64446 (Nov 14, 2025):** Fortinet disclosed a critical (CVSS 9.8) pre-authentication relative path traversal in FortiWeb that allows unauthenticated attackers to reach an internal fwbcgi administrative CGI and bypass authentication via a forged HTTP_CGIINFO header, resulting in full remote administrative control; Fortinet and CISA report active exploitation and affected systems should be patched or mitigated immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.