CyberzSOC

Publication detail
← Back to advisories & guidance

Fortinet Releases Security Advisory for Relative Path Traversal Vulnerability Affecting FortiWeb Products ↗ source

November 14, 2025 CISA Alert

Summary

CISA has updated this Alert to include an additional vulnerability, CVE-2025-58034, and its relation to CVE-2025-64446, and associated resources. CISA is aware of the exploitation of two vulnerabilities, CVE-2025-64446 and CVE-2025-58034 , in Fortinet FortiWeb, a web application firewall. CISA is also aware that threat actors could exploit CVE-2025-64446 as an initial access vector and then chain CVE-2025-58034 to escalate privileges on a target system. These vulnerabilities chained together could lead to unauthenticated remote code execution against vulnerable FortiWeb products. CVE-2025-64446 is a relative path traversal vulnerability ( CWE-23: Relative Path Traversal ) that may allow an unauthenticated malicious actor to execute administrative commands on a system via specially crafted HTTP or HTTPS requests. CVE-2025-58034 is an OS Command Injection vulnerability ( CWE-78: Improper Neutralization of Special Elements used in an OS Command [‘OS Command Injection’] ) that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-64446 9.4 Critical Fortinet FortiWeb Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on t…
CVE-2025-58034 6.7 Medium Fortinet FortiWeb Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underly…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.