CVE-2025-64446
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.
Description
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
Weakness: CWE-23
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiWeb Check your version | Web & Application Security | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiWeb
Credit
Internal
Vendor remediation
Upgrade to FortiWeb version 8.0.2 or above Upgrade to FortiWeb version 7.6.5 or above Upgrade to FortiWeb version 7.4.10 or above Upgrade to FortiWeb version 7.2.12 or above Upgrade to FortiWeb version 7.0.12 or above