← Vulnerability feed

Vulnerability record · CVE-2025-25257 · published 17 July 2025

CVE-2025-25257: FortiWeb unauthenticated SQL injection via HTTP requests

Fortinet · Fortiweb

FortiWeb versions 7.0.0 through 7.6.3 contain a CWE-89 SQL injection flaw that lets an unauthenticated attacker run unauthorized SQL code or commands through crafted HTTP or HTTPS requests. Because it is remotely reachable without credentials and rated CVSS 9.8, it is a severe pre-auth issue for internet-facing FortiWeb deployments.

9.8 CVSS 3.1 Critical CISA KEV since 18 Jul 2025 EPSS 100% · top 0.1% CWE-89 · SQL injection
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote SQL injection with CVSS 9.8, active KEV listing, public exploits and near-maximum EPSS make this an urgent patch-first issue.

What it is

FortiWeb versions 7.0.0 through 7.6.3 contain a CWE-89 SQL injection flaw that lets an unauthenticated attacker run unauthorized SQL code or commands through crafted HTTP or HTTPS requests. Because it is remotely reachable without credentials and rated CVSS 9.8, it is a severe pre-auth issue for internet-facing FortiWeb deployments.

Impact

An attacker can execute arbitrary SQL statements and commands on the appliance, potentially reading or altering its database and underlying system. Full compromise of confidentiality, integrity and availability is possible per the CVSS vector.

Attack surface

Reached over the network via crafted HTTP or HTTPS requests to the FortiWeb appliance; the CVSS vector shows no privileges required and no user interaction. Any internet-exposed management or service interface is the likely entry point.

Exploitation

CVE-2025-25257 was added to CISA KEV on 2025-07-18 with a 2025-08-08 remediation due date, and public exploit references exist on Exploit-DB and Packet Storm. EPSS is 0.99775 (99.955th percentile), indicating very high predicted exploitation activity.

What to do

  • Apply the Fortinet FortiWeb update referenced in advisory FG-IR-25-151 for your branch (7.0, 7.2, 7.4, 7.6).
  • If patching cannot be done immediately, follow the vendor mitigation guidance or discontinue use of the exposed product per CISA BOD 22-01.
  • Remove FortiWeb management and service interfaces from direct internet exposure and restrict access to trusted networks.
  • Audit and rotate any credentials or secrets stored on or reachable from the appliance, assuming possible database or command access.
  • Monitor Fortinet PSIRT and CISA KEV for updated guidance and confirm remediation by the 2025-08-08 due date.

Detection

  • Inspect HTTP/HTTPS request logs and WAF/IDS alerts for SQL injection patterns targeting FortiWeb endpoints.
  • Review FortiWeb and backend database logs for unexpected SQL statements, errors, or command execution around the time of suspicious requests.
  • Hunt for anomalous outbound connections or new processes on the appliance that could indicate post-exploitation activity.
  • Correlate network traffic to FortiWeb management interfaces from untrusted sources and alert on any such access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-25257 to the Known Exploited Vulnerabilities catalog on 18 July 2025 as "Fortinet FortiWeb SQL Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 8 August 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-25257 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed9.8CVE-2025-64446FortiWeb relative path traversal allows admin command executionFortiWeb contains a relative path traversal flaw (CWE-23) reachable through crafted HTTP or HTTPS requests. Successful exploitation lets an attacker …KEVEPSS 92%analysed7.2CVE-2025-58034FortiWeb OS command injection via crafted HTTP or CLI inputFortiWeb versions 7.0.0 through 8.0.1 contain an OS command injection flaw (CWE-78) that lets an authenticated attacker run unauthorized code on the …KEVEPSS 56%analysed9.8CVE-2026-26035Fortinet fortiweb improper authentication vulnerabilityAn Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4…EPSS 0.75%9.8CVE-2025-59719Fortinet fortiweb improper verification of cryptographic signature vulnerabilityAn improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.…EPSS 29%9.8CVE-2023-25610Fortinet fortiweb vulnerabilityA buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0…EPSS 18%9.8CVE-2024-55594Fortinet fortiweb vulnerabilityAn improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0…EPSS 0.52%9.8CVE-2023-42784Fortinet fortiweb vulnerabilityAn improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 …EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2025-25257), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.