ZeroHour

CVE-2025-64446

KEV PoC large1

Unauthenticated Path Traversal in Fortinet FortiWeb Enables Admin Command Execution

CISA: Fortinet FortiWeb Path Traversal Vulnerability

CVSS 3.1
9.8 critical
EPSS
92%p100
Published
()
KEV added
AI analysis

CVE-2025-64446 is a relative path traversal vulnerability (CWE-23) in Fortinet's FortiWeb web application firewall that can be triggered by unauthenticated attackers sending crafted HTTP or HTTPS requests to the appliance. Because the flaw occurs in the management plane, an attacker who successfully exploits it gains the ability to execute administrative commands on the device without credentials — effectively an authentication bypass, and news reporting indicates attackers have used it to create rogue admin accounts. Any organization running a FortiWeb release in the affected ranges (7.0.0 through 8.0.1 across the 7.0, 7.2, 7.4, 7.6, and 8.0 branches) is exposed, especially if the management interface is reachable from the internet. The vulnerability is being actively exploited: a public PoC/exploit exists (watchTowr), it carries a critical CVSS 9.8 score, a very high EPSS of 91.8% (100th percentile), and CISA added it to the KEV catalog on 2025-11-14 with a short remediation deadline for federal agencies.

What to do: Upgrade FortiWeb immediately to a fixed release per Fortinet's advisory — every branch listed in the affected ranges (7.0.x through 8.0.x) has a patched build, so move beyond the listed versions on your branch. Until patched, restrict HTTP/HTTPS access to the FortiWeb management interface to trusted networks/IPs and review the device for unexpected administrator accounts and unfamiliar activity, since reported attacks created rogue admin users. Federal agencies must apply vendor mitigations or discontinue use per BOD 22-01 under the KEV deadline; note the separately tracked FortiWeb CVE-2025-58034 is also being exploited and should be included in the same patch cycle.

Affected
Fortinet FortiWeb7.0.0 through 7.0.11
Fortinet FortiWeb7.2.0 through 7.2.11
Fortinet FortiWeb7.4.0 through 7.4.9
Fortinet FortiWeb7.6.0 through 7.6.4
Fortinet FortiWeb8.0.0 through 8.0.1
Estimated exposure
large≈ tens of thousands of internet-exposed FortiWeb appliances (public scan data shows on the order of 10,000–100,000 exposed FortiWeb instances; total… — FortiWeb WAF appliances are typically placed at the network edge, and public internet scan datasets (e.g., Shodan/Censys) have historically catalogued tens of thousands of exposed FortiWeb management interfaces, with many more units…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

CISA Known Exploited Vulnerability
Affected
Fortinet FortiWeb
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
fortinet
Products
fortiweb
Weakness
CWE-23
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news