Vulnerability record · CVE-2025-58034 · published 18 November 2025
CVE-2025-58034: FortiWeb OS command injection via crafted HTTP or CLI input
Fortinet · Fortiweb
FortiWeb versions 7.0.0 through 8.0.1 contain an OS command injection flaw (CWE-78) that lets an authenticated attacker run unauthorized code on the underlying system using crafted HTTP requests or CLI commands. It matters because the product sits at the network edge and the flaw is already listed in CISA KEV with a short remediation deadline.
Description
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw allows authenticated remote command execution on an edge appliance and is listed in CISA KEV with a one-week remediation deadline.
What it is
FortiWeb versions 7.0.0 through 8.0.1 contain an OS command injection flaw (CWE-78) that lets an authenticated attacker run unauthorized code on the underlying system using crafted HTTP requests or CLI commands. It matters because the product sits at the network edge and the flaw is already listed in CISA KEV with a short remediation deadline.
Impact
An attacker with valid credentials gains arbitrary command execution on the FortiWeb host, which can lead to full compromise of the appliance and any data or trust relationships it holds.
Attack surface
Reachable over the network (AV:N) with no user interaction (UI:N), but it requires high privileges (PR:H), meaning the attacker must already hold an authenticated administrative or similarly privileged account.
Exploitation
CVE-2025-58034 was added to CISA KEV on 2025-11-18 with a due date of 2025-11-25, indicating known exploitation in the wild; EPSS 30-day probability is 0.5558 (99th percentile). No ransomware campaign use is documented.
What to do
- Upgrade FortiWeb to a fixed release per Fortinet PSIRT advisory FG-IR-25-513; patch first.
- If patching is not immediately possible, apply the vendor's documented workarounds or restrict management access to trusted networks.
- Enforce least privilege and strong authentication on FortiWeb administrative and CLI accounts, and audit for unused or shared accounts.
- Segment the FortiWeb appliance from sensitive internal systems to limit lateral movement if it is compromised.
- Follow BOD 22-01 guidance for cloud-hosted instances or discontinue use if mitigations are unavailable.
Detection
- Monitor FortiWeb and upstream logs for suspicious HTTP requests or CLI commands containing shell metacharacters or unexpected process invocations.
- Alert on unexpected child processes or command shells spawned by the FortiWeb web or management service.
- Review authentication logs for anomalous or off-hours administrative logins preceding command execution.
- Hunt for new outbound connections or file changes on the FortiWeb host that do not match normal appliance behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-58034 to the Known Exploited Vulnerabilities catalog on 18 November 2025 as "Fortinet FortiWeb OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 25 November 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-513 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-58034 | US Government Resource |
Track CVE-2025-58034 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-58034), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.