CVE-2025-66178

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow an authenticated attacked to execute arbitrary commands via a specialy crafted HTTP request.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

12 Mar 2026, 20:26

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
First Time Fortinet
Fortinet fortiweb
References () https://fortiguard.fortinet.com/psirt/FG-IR-26-088 - () https://fortiguard.fortinet.com/psirt/FG-IR-26-088 - Vendor Advisory
Summary
  • (es) Una vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('inyección de comandos del sistema operativo') en Fortinet FortiWeb 8.0.0 hasta 8.0.1, FortiWeb 7.6.0 hasta 7.6.5, FortiWeb 7.4.0 hasta 7.4.11, FortiWeb 7.2.0 hasta 7.2.12, FortiWeb 7.0.0 hasta 7.0.12 puede permitir a un atacante autenticado ejecutar comandos arbitrarios mediante una solicitud HTTP especialmente diseñada.

10 Mar 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 18:17

Updated : 2026-03-12 20:26


NVD link : CVE-2025-66178

Mitre link : CVE-2025-66178

CVE.ORG link : CVE-2025-66178


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')