Critical Vulnerability Exposes Fortinet FortiWeb to Full Takeover (CVE-2025-25257)
ID: 385132eb-f39e-5d08-95d7-8fdd5e9d0a33
STIX ID: report--385132eb-f39e-5d08-95d7-8fdd5e9d0a33
Feed Name: HackRead
Threat Score
WatchTowr Labs and other researchers disclosed CVE-2025-25257, an unauthenticated SQL injection in Fortinet FortiWeb's Fabric Connector that can be escalated to remote code execution and full system compromise by abusing MySQL INTO OUTFILE and a root-privileged DB process; multiple FortiWeb versions are affected and Fortinet has published patches and a temporary mitigation (disable HTTP/HTTPS admin) — update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
