CVE-2025-53609

A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

10 Sep 2025, 15:14

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
First Time Fortinet fortiweb
Fortinet
References () https://fortiguard.fortinet.com/psirt/FG-IR-25-512 - () https://fortiguard.fortinet.com/psirt/FG-IR-25-512 - Vendor Advisory

09 Sep 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-09 14:15

Updated : 2025-09-10 15:14


NVD link : CVE-2025-53609

Mitre link : CVE-2025-53609

CVE.ORG link : CVE-2025-53609


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-23

Relative Path Traversal