CVE-2025-47857

A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privi

Severity
Medium 6.5
CVSS 3.1
Exploited
Not listed
EPSS
0.005
39.1th percentile
Discovered by
Not disclosed
Published
Aug 12, 2025
Assigned by fortinet

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands.

Weakness: CWE-78

Affected products

Vendor Product Category Matched by
Fortinet FortiWeb Web & Application Security cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiWeb

Vendor remediation

Please upgrade to FortiWeb version 7.6.4 or above Please upgrade to FortiWeb version 7.4.9 or above