CVE-2025-52970

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

15 Aug 2025, 12:26

Type Values Removed Values Added
First Time Fortinet fortiweb
Fortinet
CPE cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
References () https://fortiguard.fortinet.com/psirt/FG-IR-25-448 - () https://fortiguard.fortinet.com/psirt/FG-IR-25-448 - Vendor Advisory
References () https://pwner.gg/blog/2025-08-13-fortiweb-cve-2025-52970 - () https://pwner.gg/blog/2025-08-13-fortiweb-cve-2025-52970 - Exploit, Third Party Advisory

14 Aug 2025, 19:15

Type Values Removed Values Added
References
  • () https://pwner.gg/blog/2025-08-13-fortiweb-cve-2025-52970 -

13 Aug 2025, 17:33

Type Values Removed Values Added
Summary
  • (es) Un manejo inadecuado de los parámetros en Fortinet FortiWeb versiones 7.6.3 y anteriores, versiones 7.4.7 y anteriores, versiones 7.2.10 y anteriores, y 7.0.10 y anteriores puede permitir que un atacante remoto no autenticado con información no pública perteneciente al dispositivo y al usuario objetivo obtenga privilegios de administrador en el dispositivo a través de una solicitud especialmente manipulada.

12 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-12 19:15

Updated : 2025-08-15 12:26


NVD link : CVE-2025-52970

Mitre link : CVE-2025-52970

CVE.ORG link : CVE-2025-52970


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-233

Improper Handling of Parameters