CVE-2025-64446

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

20 Nov 2025, 22:16

Type Values Removed Values Added
References
  • {'url': 'https://github.com/nu11secur1ty/CVE-mitre/tree/main/2025/CVE-2025-64446/8.0.0', 'tags': ['Exploit', 'Third Party Advisory'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}
  • {'url': 'https://www.patreon.com/posts/cve-2025-64446-8-143791801', 'tags': ['Exploit'], 'source': 'af854a3a-2127-422b-91ae-364da2661108'}

19 Nov 2025, 18:35

Type Values Removed Values Added
References () https://github.com/nu11secur1ty/CVE-mitre/tree/main/2025/CVE-2025-64446/8.0.0 - () https://github.com/nu11secur1ty/CVE-mitre/tree/main/2025/CVE-2025-64446/8.0.0 - Exploit, Third Party Advisory
References () https://www.patreon.com/posts/cve-2025-64446-8-143791801 - () https://www.patreon.com/posts/cve-2025-64446-8-143791801 - Exploit

19 Nov 2025, 15:15

Type Values Removed Values Added
References
  • () https://github.com/nu11secur1ty/CVE-mitre/tree/main/2025/CVE-2025-64446/8.0.0 -
  • () https://www.patreon.com/posts/cve-2025-64446-8-143791801 -

14 Nov 2025, 18:17

Type Values Removed Values Added
References () https://fortiguard.fortinet.com/psirt/FG-IR-25-910 - () https://fortiguard.fortinet.com/psirt/FG-IR-25-910 - Vendor Advisory
References () https://github.com/watchtowrlabs/watchTowr-vs-Fortiweb-AuthBypass - () https://github.com/watchtowrlabs/watchTowr-vs-Fortiweb-AuthBypass - Exploit, Third Party Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-64446 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-64446 - US Government Resource
CPE cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
First Time Fortinet
Fortinet fortiweb

14 Nov 2025, 18:15

Type Values Removed Values Added
References
  • () https://github.com/watchtowrlabs/watchTowr-vs-Fortiweb-AuthBypass -

14 Nov 2025, 17:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-64446 -

14 Nov 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-14 16:15

Updated : 2025-11-20 22:16


NVD link : CVE-2025-64446

Mitre link : CVE-2025-64446

CVE.ORG link : CVE-2025-64446


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-23

Relative Path Traversal