← Vulnerability feed

Vulnerability record · CVE-2025-25254 · published 8 April 2025

CVE-2025-25254: Fortinet fortiweb path traversal vulnerability

Fortinet · Fortiweb

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all versions, 7.0 all versions endpoint may allow an authenticated admin to access and modify the filesystem via crafted requests.

7.2 CVSS 3.1 High EPSS 17% · top 3.0% CWE-22 · Path traversal
7.2CVSS 3.1 base score
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all versions, 7.0 all versions endpoint may allow an authenticated admin to access and modify the filesystem via crafted requests.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-25254 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed9.8CVE-2025-64446FortiWeb relative path traversal allows admin command executionFortiWeb contains a relative path traversal flaw (CWE-23) reachable through crafted HTTP or HTTPS requests. Successful exploitation lets an attacker …KEVEPSS 92%analysed9.8CVE-2025-25257FortiWeb unauthenticated SQL injection via HTTP requestsFortiWeb versions 7.0.0 through 7.6.3 contain a CWE-89 SQL injection flaw that lets an unauthenticated attacker run unauthorized SQL code or commands…KEVEPSS 100%analysed7.2CVE-2025-58034FortiWeb OS command injection via crafted HTTP or CLI inputFortiWeb versions 7.0.0 through 8.0.1 contain an OS command injection flaw (CWE-78) that lets an authenticated attacker run unauthorized code on the …KEVEPSS 56%analysed9.8CVE-2026-26035Fortinet fortiweb improper authentication vulnerabilityAn Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4…EPSS 0.75%9.8CVE-2025-59719Fortinet fortiweb improper verification of cryptographic signature vulnerabilityAn improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.…EPSS 29%9.8CVE-2023-25610Fortinet fortiweb vulnerabilityA buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0…EPSS 18%9.8CVE-2024-55594Fortinet fortiweb vulnerabilityAn improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0…EPSS 0.52%

Source: NIST National Vulnerability Database (record CVE-2025-25254), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.