FortiWeb CVE-2025-64446 Vulnerability: Path Traversal Leads to Remote Code Execution
ID: e3a65c67-2173-5ddb-9997-d1a02afa09e1
STIX ID: report--e3a65c67-2173-5ddb-9997-d1a02afa09e1
Feed Name: Resources-2
Threat Score
**FortiWeb CVE-2025-64446 (Nov 14, 2025):** Fortinet disclosed a critical (CVSS 9.8) pre-authentication relative path traversal in FortiWeb that allows unauthenticated attackers to reach an internal fwbcgi administrative CGI and bypass authentication via a forged HTTP_CGIINFO header, resulting in full remote administrative control; Fortinet and CISA report active exploitation and affected systems should be patched or mitigated immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
