ZeroHour

CVE-2025-52970

PoC
CVSS 3.1
8.1 high
EPSS
10%p95
Published
()
Modified
Description

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.

Vendors
fortinet
Products
fortiweb
Weakness
CWE-233
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news