Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited in the Wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-58034 | Authenticated OS Command Injection RCE in Fortinet FortiWeb (active exploitation) Fortinet FortiWeb contains an OS command injection flaw (CWE-78) that allows an authenticated attacker to execute unauthorized code on the underlying system by sending crafted HTTP requests or CLI commands. The CVSS vector shows a network-based attack that requires high-privilege (administrative) credentials, so abuse typically follows credential compromise or misuse of a legitimate admin session. Successful exploitation yields high-impact code execution with high confidentiality, integrity, and availability impact on the appliance or virtual machine. Affected deployments span every currently supported FortiWeb branch: 7.0.0-7.0.11, 7.2.0-7.2.11, 7.4.0-7.4.10, 7.6.0-7.6.5, and 8.0.0-8.0.1. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2025-11-18, EPSS assigns a 55.6% 30-day exploitation probability (99th percentile), and media reports describe it as quietly patched by Fortinet before disclosure under active exploitation. Do: Upgrade FortiWeb to a fixed release in your branch per the Fortinet PSIRT advisory (any release beyond the affected ranges above); because the fix was reportedly included quietly in earlier updates, verify your running version before assuming you are safe. Until patched, restrict administrative access (HTTP/HTTPS management interface and CLI) to trusted networks and review admin logs for unexpected logins or commands; U.S. federal agencies must apply mitigations per vendor instructions or follow BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable. | 7.2 | 56% | KEV |
| largetens of thousands of deployed FortiWeb appliances/virtual appliances (public scans typically show thousands-to-tens-of-thousands of FortiWeb instances… | |
| CVE-2025-64446 | Unauthenticated Path Traversal in Fortinet FortiWeb Enables Admin Command Execution CVE-2025-64446 is a relative path traversal vulnerability (CWE-23) in Fortinet's FortiWeb web application firewall that can be triggered by unauthenticated attackers sending crafted HTTP or HTTPS requests to the appliance. Because the flaw occurs in the management plane, an attacker who successfully exploits it gains the ability to execute administrative commands on the device without credentials — effectively an authentication bypass, and news reporting indicates attackers have used it to create rogue admin accounts. Any organization running a FortiWeb release in the affected ranges (7.0.0 through 8.0.1 across the 7.0, 7.2, 7.4, 7.6, and 8.0 branches) is exposed, especially if the management interface is reachable from the internet. The vulnerability is being actively exploited: a public PoC/exploit exists (watchTowr), it carries a critical CVSS 9.8 score, a very high EPSS of 91.8% (100th percentile), and CISA added it to the KEV catalog on 2025-11-14 with a short remediation deadline for federal agencies. Do: Upgrade FortiWeb immediately to a fixed release per Fortinet's advisory — every branch listed in the affected ranges (7.0.x through 8.0.x) has a patched build, so move beyond the listed versions on your branch. Until patched, restrict HTTP/HTTPS access to the FortiWeb management interface to trusted networks/IPs and review the device for unexpected administrator accounts and unfamiliar activity, since reported attacks created rogue admin users. Federal agencies must apply vendor mitigations or discontinue use per BOD 22-01 under the KEV deadline; note the separately tracked FortiWeb CVE-2025-58034 is also being exploited and should be included in the same patch cycle. | 9.8 | 92% | KEV PoC |
| large≈ tens of thousands of internet-exposed FortiWeb appliances (public scan data shows on the order of 10,000–100,000 exposed FortiWeb instances; total… |
Full article488 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananNov 19, 2025Vulnerability / Network Security
Fortinet has warned of a new security flaw in FortiWeb that it said has been exploited in the wild.
The medium-severity vulnerability, tracked as CVE-2025-58034, carries a CVSS score of 6.7 out of a maximum of 10.0.
"An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands," the company said in a Tuesday advisory.
In other words, successful attacks require an attacker to first authenticate themselves through some other means and chain it with CVE-2025-58034 to execute arbitrary operating system commands.
It has been addressed in the following versions -
- FortiWeb 8.0.0 through 8.0.1 (Upgrade to 8.0.2 or above)
- FortiWeb 7.6.0 through 7.6.5 (Upgrade to 7.6.6 or above)
- FortiWeb 7.4.0 through 7.4.10 (Upgrade to 7.4.11 or above)
- FortiWeb 7.2.0 through 7.2.11 (Upgrade to 7.2.12 or above)
- FortiWeb 7.0.0 through 7.0.11 (Upgrade to 7.0.12 or above)
The company credited Trend Micro researcher Jason McFadyen for reporting the flaw under its responsible disclosure policy.
Interestingly, the development comes days after Fortinet confirmed that it silently patched another critical FortiWeb vulnerability (CVE-2025-64446, CVSS score: 9.1) in version 8.0.2. Although the company has not clarified if the exploitation activity is linked, Orange Cyberdefense said it observed "several exploitation campaigns" chaining CVE-2025-58034 with CVE-2025-64446 to facilitate authentication bypass and command injection.
"The timeline for both vulnerabilities being disclosed is only days apart. Both vulnerabilities were patched by the vendor in prior product updates and with no disclosure at the time of patching," cybersecurity company Rapid7 said.
"There is an obvious utility of chaining an authentication bypass to an authenticated command injection. Given all of these things, it seems highly likely these two vulnerabilities comprise an exploit chain for unauthenticated remote code execution against vulnerable FortiWeb devices."
"We activated our PSIRT response and remediation efforts as soon as we learned of this matter, and those efforts remain ongoing," a Fortinet spokesperson told The Hacker News. "Fortinet diligently balances our commitment to the security of our customers and our culture of responsible transparency."
It's currently not clear why Fortinet opted to patch the flaws without releasing an advisory. But the move has left defenders at a disadvantage, effectively preventing them from mounting an adequate response.
"When popular technology vendors fail to communicate new security issues, they are issuing an invitation to attackers while choosing to keep that same information from defenders," VulnCheck noted last week.
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the security defect to its Known Exploited Vulnerabilities (KEV) catalog, urging Federal Civilian Executive Branch (FCEB) agencies to patch it by November 25, 2025.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/11/fortinet-warns-of-new-fortiweb-cve-2025.html