CVE-2025-66178

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow an authenticated attacked to execute arbitrary commands via a specialy crafted HTTP request.
Configurations

No configuration.

History

10 Mar 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 18:17

Updated : 2026-03-10 18:17


NVD link : CVE-2025-66178

Mitre link : CVE-2025-66178

CVE.ORG link : CVE-2025-66178


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')