PT-2025-47361 · Fortinet · Fortiweb
Published
2025-11-18
·
Updated
2025-12-26
·
CVE-2025-58034
CVSS v2.0
9.0
9.0
High
| Base vector | Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiWeb versions 7.0.0 through 8.0.1
Fortinet FortiWeb versions 7.2.0 through 7.2.11
Fortinet FortiWeb versions 7.4.0 through 7.4.10
Fortinet FortiWeb versions 7.6.0 through 7.6.5
Description
Fortinet FortiWeb is affected by an OS Command Injection vulnerability. An authenticated attacker can execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands. This vulnerability is actively exploited in the wild and has been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability allows an attacker to execute commands with system-level privileges, potentially leading to data breaches, ransomware attacks, and significant financial losses. Approximately 1.5k instances are exposed. The vulnerability is related to the improper neutralization of special elements used in OS commands.
Recommendations
Fortinet FortiWeb versions 7.0.0 through 7.0.11: Apply the latest available patch.
Fortinet FortiWeb versions 7.2.0 through 7.2.11: Apply the latest available patch.
Fortinet FortiWeb versions 7.4.0 through 7.4.10: Apply the latest available patch.
Fortinet FortiWeb versions 7.6.0 through 7.6.5: Apply the latest available patch.
Fortinet FortiWeb versions 8.0.0 through 8.0.1: Apply the latest available patch.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-14466
CVE-2025-58034
ZDI-25-1014
Affected Products
Fortiweb
References · 116
- https://bdu.fstec.ru/vul/2025-14466 · Security Note
- https://safe-surf.ru/specialists/bulletins-nkcki/726880 · Security Note
- https://zerodayinitiative.com/advisories/ZDI-25-1014 · Security Note
- https://fortiguard.fortinet.com/psirt/FG-IR-25-513 · Security Note, Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-58034 · Security Note
- https://twitter.com/blackorbird/status/2004137586353230078 · Twitter Post
- https://t.me/pentestingnews/71048 · Telegram Post
- https://twitter.com/HunterMapping/status/1991031605276680249 · Twitter Post
- https://t.me/cveNotify/143298 · Telegram Post
- https://twitter.com/JamaalChalid/status/1991929705314795578 · Twitter Post
- https://twitter.com/corerouter/status/1990889979157869034 · Twitter Post
- https://t.me/cKure/16590 · Telegram Post
- https://twitter.com/Alevskey/status/1991008903161684060 · Twitter Post
- https://twitter.com/ncsc_gov_ie/status/1991895279185117524 · Twitter Post
- https://twitter.com/zoomeye_team/status/1991087526678085693 · Twitter Post