Vulnerability record · CVE-2025-25257 · published 17 July 2025
CVE-2025-25257: FortiWeb unauthenticated SQL injection via HTTP requests
Fortinet · Fortiweb
FortiWeb versions 7.0.0 through 7.6.3 contain a CWE-89 SQL injection flaw that lets an unauthenticated attacker run unauthorized SQL code or commands through crafted HTTP or HTTPS requests. Because it is remotely reachable without credentials and rated CVSS 9.8, it is a severe pre-auth issue for internet-facing FortiWeb deployments.
Description
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote SQL injection with CVSS 9.8, active KEV listing, public exploits and near-maximum EPSS make this an urgent patch-first issue.
What it is
FortiWeb versions 7.0.0 through 7.6.3 contain a CWE-89 SQL injection flaw that lets an unauthenticated attacker run unauthorized SQL code or commands through crafted HTTP or HTTPS requests. Because it is remotely reachable without credentials and rated CVSS 9.8, it is a severe pre-auth issue for internet-facing FortiWeb deployments.
Impact
An attacker can execute arbitrary SQL statements and commands on the appliance, potentially reading or altering its database and underlying system. Full compromise of confidentiality, integrity and availability is possible per the CVSS vector.
Attack surface
Reached over the network via crafted HTTP or HTTPS requests to the FortiWeb appliance; the CVSS vector shows no privileges required and no user interaction. Any internet-exposed management or service interface is the likely entry point.
Exploitation
CVE-2025-25257 was added to CISA KEV on 2025-07-18 with a 2025-08-08 remediation due date, and public exploit references exist on Exploit-DB and Packet Storm. EPSS is 0.99775 (99.955th percentile), indicating very high predicted exploitation activity.
What to do
- Apply the Fortinet FortiWeb update referenced in advisory FG-IR-25-151 for your branch (7.0, 7.2, 7.4, 7.6).
- If patching cannot be done immediately, follow the vendor mitigation guidance or discontinue use of the exposed product per CISA BOD 22-01.
- Remove FortiWeb management and service interfaces from direct internet exposure and restrict access to trusted networks.
- Audit and rotate any credentials or secrets stored on or reachable from the appliance, assuming possible database or command access.
- Monitor Fortinet PSIRT and CISA KEV for updated guidance and confirm remediation by the 2025-08-08 due date.
Detection
- Inspect HTTP/HTTPS request logs and WAF/IDS alerts for SQL injection patterns targeting FortiWeb endpoints.
- Review FortiWeb and backend database logs for unexpected SQL statements, errors, or command execution around the time of suspicious requests.
- Hunt for anomalous outbound connections or new processes on the appliance that could indicate post-exploitation activity.
- Correlate network traffic to FortiWeb management interfaces from untrusted sources and alert on any such access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-25257 to the Known Exploited Vulnerabilities catalog on 18 July 2025 as "Fortinet FortiWeb SQL Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 8 August 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-151 | Vendor Advisory |
| https://packetstorm.news/files/id/210193/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/52473 | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/0xbigshaq/CVE-2025-25257 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25257 | US Government Resource |
Track CVE-2025-25257 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-25257), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.