← Vulnerability feed

Vulnerability record · CVE-2025-58034 · published 18 November 2025

CVE-2025-58034: FortiWeb OS command injection via crafted HTTP or CLI input

Fortinet · Fortiweb

FortiWeb versions 7.0.0 through 8.0.1 contain an OS command injection flaw (CWE-78) that lets an authenticated attacker run unauthorized code on the underlying system using crafted HTTP requests or CLI commands. It matters because the product sits at the network edge and the flaw is already listed in CISA KEV with a short remediation deadline.

7.2 CVSS 3.1 High CISA KEV since 18 Nov 2025 EPSS 56% · top 1.0% CWE-78 · OS command injection
7.2CVSS 3.1 base score
56%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw allows authenticated remote command execution on an edge appliance and is listed in CISA KEV with a one-week remediation deadline.

What it is

FortiWeb versions 7.0.0 through 8.0.1 contain an OS command injection flaw (CWE-78) that lets an authenticated attacker run unauthorized code on the underlying system using crafted HTTP requests or CLI commands. It matters because the product sits at the network edge and the flaw is already listed in CISA KEV with a short remediation deadline.

Impact

An attacker with valid credentials gains arbitrary command execution on the FortiWeb host, which can lead to full compromise of the appliance and any data or trust relationships it holds.

Attack surface

Reachable over the network (AV:N) with no user interaction (UI:N), but it requires high privileges (PR:H), meaning the attacker must already hold an authenticated administrative or similarly privileged account.

Exploitation

CVE-2025-58034 was added to CISA KEV on 2025-11-18 with a due date of 2025-11-25, indicating known exploitation in the wild; EPSS 30-day probability is 0.5558 (99th percentile). No ransomware campaign use is documented.

What to do

  • Upgrade FortiWeb to a fixed release per Fortinet PSIRT advisory FG-IR-25-513; patch first.
  • If patching is not immediately possible, apply the vendor's documented workarounds or restrict management access to trusted networks.
  • Enforce least privilege and strong authentication on FortiWeb administrative and CLI accounts, and audit for unused or shared accounts.
  • Segment the FortiWeb appliance from sensitive internal systems to limit lateral movement if it is compromised.
  • Follow BOD 22-01 guidance for cloud-hosted instances or discontinue use if mitigations are unavailable.

Detection

  • Monitor FortiWeb and upstream logs for suspicious HTTP requests or CLI commands containing shell metacharacters or unexpected process invocations.
  • Alert on unexpected child processes or command shells spawned by the FortiWeb web or management service.
  • Review authentication logs for anomalous or off-hours administrative logins preceding command execution.
  • Hunt for new outbound connections or file changes on the FortiWeb host that do not match normal appliance behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-58034 to the Known Exploited Vulnerabilities catalog on 18 November 2025 as "Fortinet FortiWeb OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 25 November 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-58034 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed9.8CVE-2025-64446FortiWeb relative path traversal allows admin command executionFortiWeb contains a relative path traversal flaw (CWE-23) reachable through crafted HTTP or HTTPS requests. Successful exploitation lets an attacker …KEVEPSS 92%analysed9.8CVE-2025-25257FortiWeb unauthenticated SQL injection via HTTP requestsFortiWeb versions 7.0.0 through 7.6.3 contain a CWE-89 SQL injection flaw that lets an unauthenticated attacker run unauthorized SQL code or commands…KEVEPSS 100%analysed9.8CVE-2026-26035Fortinet fortiweb improper authentication vulnerabilityAn Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4…EPSS 0.75%9.8CVE-2025-59719Fortinet fortiweb improper verification of cryptographic signature vulnerabilityAn improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.…EPSS 29%9.8CVE-2023-25610Fortinet fortiweb vulnerabilityA buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0…EPSS 18%9.8CVE-2024-55594Fortinet fortiweb vulnerabilityAn improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0…EPSS 0.52%9.8CVE-2023-42784Fortinet fortiweb vulnerabilityAn improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 …EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2025-58034), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.