Loading HuntDB...

CVE-2025-25257

CRITICAL
Published 2025-07-17T15:10:04.532Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-25257. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
9.6
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C
Base Score Metrics
Exploitability: N/A Impact: N/A

Attack Vector Metrics

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED

Impact Metrics

Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Description

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and below 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Available Exploits

No exploits available for this CVE.

Related News

GreenboneOS: CVE-2025-25257: Urgent Pre-Auth RCE in FortiWeb Fabric Connector

A fresh vulnerability, CVE-2025-25257 (CVSS 9.6) in Fortinet’s FortiWeb Fabric Connector presents high risk globally. Although the CVE is still only in RESERVED status as of July 14th, 2025, it has already received a national CERT advisory from Belgium’s CERT…

Greenbone.net 2025-07-21 11:21
U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiWeb flaw, tracked as CVE-2025-25257, …

Securityaffairs.com 2025-07-20 13:38
Fortinet FortiWeb flaw CVE-2025-25257 exploited hours after PoC release

Hackers exploited a Fortinet FortiWeb flaw the same day a PoC was published, compromising dozens of systems. Hackers began exploiting a critical Fortinet FortiWeb flaw, tracked as CVE-2025-25257 (CVSS score of 9.6), on the same day a proof-of-concept (PoC) ex…

Securityaffairs.com 2025-07-19 16:25
CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-25257 Fortinet FortiWeb SQL Injection Vulnerability These types of vulnerabilities are frequ…

Cisa.gov 2025-07-18 12:00
New Fortinet FortiWeb hacks likely linked to public RCE exploits

Multiple Fortinet FortiWeb instances recently infected with web shells are believed to have been compromised using public exploits for a recently patched remote code execution (RCE) flaw tracked as CVE-2025-25257. [...]

BleepingComputer 2025-07-16 14:58

Affected Products

Known Exploited Vulnerability

This vulnerability is actively being exploited in the wild

View KEV Details

Remediation Status

Due Soon

Due Date

August 8, 2025 (14 days remaining)

Added to KEV

July 18, 2025

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected Product

Vendor/Project: Fortinet
Product: FortiWeb

Ransomware Risk

Known Ransomware Use
KEV Catalog Version: 2025.07.18 Released: July 18, 2025

EU Vulnerability Database

Monitored by ENISA for EU cybersecurity

EU Coordination

EU Coordinated

Exploitation Status

No Known Exploitation

ENISA Analysis

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and below 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Affected Products (ENISA)

fortinet
fortiweb

ENISA Scoring

CVSS Score (3.1)

9.6
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C

EPSS Score

2.980
probability

Data provided by ENISA EU Vulnerability Database. Last updated: July 18, 2025

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed CRITICAL

GHSA-mj4r-rpwm-gg33

Advisory Details

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and below 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

CVSS Scoring

CVSS Score

9.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Advisory provided by GitHub Security Advisory Database. Published: July 17, 2025, Modified: July 17, 2025

Social Media Intelligence

Real-time discussions and threat intelligence from social platforms

7 posts
Reddit 8 hours, 21 minutes ago
MatrixToday
Exploit

Wer nutzt eigentlich noch CISCO? Cisco hat mal wieder eine neue Sicherheitslücke mit höchstem Schweregrad offengelegt, bei der Code mit erhöhten Berechtigungen ausgeführt werden kann. "These vulnerabilities are due to insufficient validation of user-supplied input. An attacker could exploit these vulnerabilities by submitting a crafted API request. A successful exploit …

3
1
5.0
View Original High Risk
Reddit 2 days, 17 hours ago
crstux
Exploit

🔥 Top 10 Trending CVEs (22/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-53816](https://nvd.nist.gov/vuln/detail/CVE-2025-53816)** - 📝 7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in …

2
2.0
View Original High Risk
Reddit 3 days, 17 hours ago
crstux
Exploit

🔥 Top 10 Trending CVEs (21/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-53771](https://nvd.nist.gov/vuln/detail/CVE-2025-53771)** - 📝 Microsoft SharePoint Server Spoofing Vulnerability - 📅 **Published:** 20/07/2025 - 📈 **CVSS:** 6.3 - 🧭 **Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C - 📣 **Mentions:** 9 - 📝 **Analysis:** A SharePoint Server spoofing …

1
1.0
View Original High Risk
Reddit 4 days, 17 hours ago
crstux
Exploit

🔥 Top 10 Trending CVEs (20/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-53770](https://nvd.nist.gov/vuln/detail/CVE-2025-53770)** - 📝 Microsoft SharePoint Server Remote Code Execution Vulnerability - 📅 **Published:** 20/07/2025 - 📈 **CVSS:** 9.8 - 🧭 **Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:W/RC:C - 📣 **Mentions:** 13 - ⚠️ **Priority:** 4 - …

1
1.0
View Original High Risk
Reddit 4 days, 17 hours ago
crstux
Exploit

🔥 Top 10 Trending CVEs (20/07/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-53770](https://nvd.nist.gov/vuln/detail/CVE-2025-53770)** - 📝 Microsoft SharePoint Server Remote Code Execution Vulnerability - 📅 **Published:** 20/07/2025 - 📈 **CVSS:** 9.8 - 🧭 **Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:W/RC:C - 📣 **Mentions:** 13 - ⚠️ **Priority:** 4 - …

1
1.0
View Original High Risk
Reddit 5 days, 7 hours ago
quellaman
Exploit PoC

Fortinet FortiWeb flaw CVE-2025-25257 exploited hours after PoC release

0.0
View Original High Risk
Reddit 1 week, 1 day ago
_cybersecurity_
Exploit

Fortinet FortiWeb Instances Under Attack Due to Public RCE Exploit **Multiple Fortinet FortiWeb instances have been compromised through a recently patched remote code execution flaw, posing a significant security threat.** **Key Points:** - Publicly disclosed exploits linked to critical RCE flaw (CVE-2025-25257) - Recent infections reported by The Shadowserver Foundation …

2
1
4.0
View Original High Risk

References

Published: 2025-07-17T15:10:04.532Z
Last Modified: 2025-07-17T15:31:33.264Z
Copied to clipboard!