peter bassill · operator
$ cve CVE-2025-25257 JSON

CVE-2025-25257 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 99.8% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-08-08.

Description

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.78% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-89
On CISA KEVyes — remediate by 2025-08-08
Public exploityes
Published2025-07-17
Last modified2026-06-17

CISA KEV

NameFortinet FortiWeb SQL Injection Vulnerability
Added2025-07-18
Due2025-08-08
Vendor / productFortinet / FortiWeb
Ransomware usenone reported

Affected (1)

VendorProduct
fortinetfortiweb

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD