logo

How to find Fortinet FortiWeb assets on your network

ID: 97fde978-c403-5ed4-87fa-2add4c9978bf

STIX ID: report--97fde978-c403-5ed4-87fa-2add4c9978bf

Feed Name: runZero Blog

Threat Score
90/100

Date Published: 2025-11-14

Date Updated: 2026-04-29

Author: Matthew Kienow

...
...

Fortinet FortiWeb is affected by two critical vulnerabilities—CVE-2025-64446 (relative path traversal leading to administrative command execution) and CVE-2025-25257 (pre-authentication SQL injection enabling arbitrary commands)—both actively exploited in the wild with high CVSS scores; Fortinet published advisories and specific version upgrades/patches to mitigate the issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.