ZeroHour

CVE-2025-58034

KEVlarge

Authenticated OS Command Injection RCE in Fortinet FortiWeb (active exploitation)

CISA: Fortinet FortiWeb OS Command Injection Vulnerability

CVSS 3.1
7.2 high
EPSS
56%p99
Published
()
KEV added
AI analysis

Fortinet FortiWeb contains an OS command injection flaw (CWE-78) that allows an authenticated attacker to execute unauthorized code on the underlying system by sending crafted HTTP requests or CLI commands. The CVSS vector shows a network-based attack that requires high-privilege (administrative) credentials, so abuse typically follows credential compromise or misuse of a legitimate admin session. Successful exploitation yields high-impact code execution with high confidentiality, integrity, and availability impact on the appliance or virtual machine. Affected deployments span every currently supported FortiWeb branch: 7.0.0-7.0.11, 7.2.0-7.2.11, 7.4.0-7.4.10, 7.6.0-7.6.5, and 8.0.0-8.0.1. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2025-11-18, EPSS assigns a 55.6% 30-day exploitation probability (99th percentile), and media reports describe it as quietly patched by Fortinet before disclosure under active exploitation.

What to do: Upgrade FortiWeb to a fixed release in your branch per the Fortinet PSIRT advisory (any release beyond the affected ranges above); because the fix was reportedly included quietly in earlier updates, verify your running version before assuming you are safe. Until patched, restrict administrative access (HTTP/HTTPS management interface and CLI) to trusted networks and review admin logs for unexpected logins or commands; U.S. federal agencies must apply mitigations per vendor instructions or follow BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable.

Affected
Fortinet FortiWeb8.0.0 - 8.0.1
Fortinet FortiWeb7.6.0 - 7.6.5
Fortinet FortiWeb7.4.0 - 7.4.10
Fortinet FortiWeb7.2.0 - 7.2.11
Fortinet FortiWeb7.0.0 - 7.0.11
Estimated exposure
largetens of thousands of deployed FortiWeb appliances/virtual appliances (public scans typically show thousands-to-tens-of-thousands of FortiWeb instances… — FortiWeb is deployed as WAF appliances/VMs at the edge of many enterprise networks, the affected ranges cover every currently supported branch (7.0 through 8.0), and public internet scans consistently reveal thousands to tens of thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

CISA Known Exploited Vulnerability
Affected
Fortinet FortiWeb
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
fortinet
Products
fortiweb
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news