CyberzSOC

Publication detail
← Back to advisories & guidance

2025-024: Critical Vulnerability in FortiWeb ↗ source

July 11, 2025 CERT-EU Advisory

Summary

The vulnerability CVE-2025-25257, with a CVSS score of 9.6, is due to an improper neutralisation of special elements used in an SQL command. It may allow an unauthenticated attacker to execute unauthorised SQL code or commands via crafted HTTP or HTTPs requests. The following product versions are affected by the vulnerability: It is recommended updating affected devices as soon as possible. It is possible to mitigate this vulnerability by disabling the HTTP/HTTPS administrative interface.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-25257 9.6 Critical Fortinet FortiWeb Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.