CVE-2025-25257
9.5 CISA KEVFortinet · FortiWeb
A critical SQL injection vulnerability in Fortinet FortiWeb allows unauthenticated attackers to execute arbitrary SQL commands via crafted HTTP requests.
Executive summary
Fortinet FortiWeb is affected by a critical SQL injection vulnerability that is currently being exploited in the wild, posing a severe risk of unauthorized command execution.
Vulnerability
This vulnerability, classified as CWE-89, involves improper neutralization of special elements used in SQL commands. An unauthenticated attacker can trigger this flaw by sending specifically crafted HTTP or HTTPS requests to the vulnerable application.
Business impact
The ability for an unauthenticated attacker to inject and execute arbitrary SQL commands represents a total compromise of the affected system. Successful exploitation could lead to full database exfiltration, modification of application data, or complete system takeover, resulting in significant operational downtime and potential regulatory non-compliance. Given the CVSS score of 9.5 and confirmed active exploitation, this vulnerability presents an extreme risk to organizational security.
Remediation
Immediate Action: Upgrade FortiWeb instances immediately to version 7.6.4, 7.4.8, 7.2.11, 7.0.11, or higher versions as provided by the vendor.
Proactive Monitoring: Monitor web server logs for suspicious HTTP requests containing SQL syntax patterns or unexpected database error messages.
Compensating Controls: Deploy or update Web Application Firewall rules to detect and block malicious SQL injection payloads targeting the FortiWeb management interface.
Exploitation status
Public Exploit Available: Yes, a public exploit exists via an ExploitDB entry and multiple proof-of-concept repositories on GitHub.
Analyst recommendation
Due to the critical severity and confirmed active exploitation of this flaw, organizations must prioritize patching their FortiWeb appliances immediately. Delaying the application of these updates exposes the network to trivial and high-impact remote exploitation. Administrators should verify the version of all FortiWeb instances and apply the vendor-supplied patches without delay to prevent unauthorized access and data compromise.
More Fortinet CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Analyst report written
- Fix documented per CVE record