CVE-2025-25257
Fortinet FortiWeb
Published 17 Jul 2025 · updated 17 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 18 Jul 2025, with a remediation deadline of 8 Aug 2025 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
References
- fortiguard.fortinet.com/psirt/FG-IR-25-151 · Vendor Advisory
- packetstorm.news/files/id/210193/ · Exploit, Third Party Advisory, VDB Entry
- www.exploit-db.com/exploits/52473 · Exploit, Third Party Advisory, VDB Entry
- github.com/0xbigshaq/CVE-2025-25257 · Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25257 · US Government Resource