CVE-2025-25257 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 99.8% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2025-08-08.
Description
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.78% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | yes — remediate by 2025-08-08 |
| Public exploit | yes |
| Published | 2025-07-17 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Fortinet FortiWeb SQL Injection Vulnerability |
|---|---|
| Added | 2025-07-18 |
| Due | 2025-08-08 |
| Vendor / product | Fortinet / FortiWeb |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| fortinet | fortiweb |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution | 2026-02-04 |
References
→ the Explorer · watch your stack · NVD