logo

Critical Vulnerability Exposes Fortinet FortiWeb to Full Takeover (CVE-2025-25257)

ID: 385132eb-f39e-5d08-95d7-8fdd5e9d0a33

STIX ID: report--385132eb-f39e-5d08-95d7-8fdd5e9d0a33

Feed Name: HackRead

Threat Score
85/100

Date Published: 2025-07-13

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

WatchTowr Labs and other researchers disclosed CVE-2025-25257, an unauthenticated SQL injection in Fortinet FortiWeb's Fabric Connector that can be escalated to remote code execution and full system compromise by abusing MySQL INTO OUTFILE and a root-privileged DB process; multiple FortiWeb versions are affected and Fortinet has published patches and a temporary mitigation (disable HTTP/HTTPS admin) — update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.