CVE-2025-25257

9.5 CISA KEV

Fortinet · FortiWeb

A critical SQL injection vulnerability in Fortinet FortiWeb allows unauthenticated attackers to execute arbitrary SQL commands via crafted HTTP requests.

Executive summary

Fortinet FortiWeb is affected by a critical SQL injection vulnerability that is currently being exploited in the wild, posing a severe risk of unauthorized command execution.

Vulnerability

This vulnerability, classified as CWE-89, involves improper neutralization of special elements used in SQL commands. An unauthenticated attacker can trigger this flaw by sending specifically crafted HTTP or HTTPS requests to the vulnerable application.

Business impact

The ability for an unauthenticated attacker to inject and execute arbitrary SQL commands represents a total compromise of the affected system. Successful exploitation could lead to full database exfiltration, modification of application data, or complete system takeover, resulting in significant operational downtime and potential regulatory non-compliance. Given the CVSS score of 9.5 and confirmed active exploitation, this vulnerability presents an extreme risk to organizational security.

Remediation

Immediate Action: Upgrade FortiWeb instances immediately to version 7.6.4, 7.4.8, 7.2.11, 7.0.11, or higher versions as provided by the vendor.

Proactive Monitoring: Monitor web server logs for suspicious HTTP requests containing SQL syntax patterns or unexpected database error messages.

Compensating Controls: Deploy or update Web Application Firewall rules to detect and block malicious SQL injection payloads targeting the FortiWeb management interface.

Exploitation status

Public Exploit Available: Yes, a public exploit exists via an ExploitDB entry and multiple proof-of-concept repositories on GitHub.

Analyst recommendation

Due to the critical severity and confirmed active exploitation of this flaw, organizations must prioritize patching their FortiWeb appliances immediately. Delaying the application of these updates exposes the network to trivial and high-impact remote exploitation. Administrators should verify the version of all FortiWeb instances and apply the vendor-supplied patches without delay to prevent unauthorized access and data compromise.

More Fortinet CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief critical section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief critical section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Analyst report written
  21. Fix documented per CVE record

Sources