{
    "id": "CVE-2025-64446",
    "published": "2025-11-14 16:15:58",
    "last_modified": "2026-06-17 09:54:23",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-23",
    "description": "A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.",
    "epss_score": "0.91838",
    "epss_percentile": "0.99815",
    "kev": 1,
    "kev_due": "2025-11-21",
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:39:59",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2025-11-21."
    },
    "products": [
        {
            "vendor": "fortinet",
            "product": "fortiweb"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2025-64446",
        "date_added": "2025-11-14",
        "due_date": "2025-11-21",
        "vendor": "Fortinet",
        "product": "FortiWeb",
        "name": "Fortinet FortiWeb Path Traversal Vulnerability",
        "ransomware": 0
    },
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "52502",
            "title": "FortiWeb  8.0.2 - Remote Code Execution",
            "date": "2026-04-08",
            "url": "https://www.exploit-db.com/exploits/52502"
        },
        {
            "source": "exploit-db",
            "ref_id": "52495",
            "title": "Fortinet FortiWeb v8.0.1 - Auth Bypass",
            "date": "2026-04-06",
            "url": "https://www.exploit-db.com/exploits/52495"
        }
    ],
    "refs_list": [
        "https://fortiguard.fortinet.com/psirt/FG-IR-25-910",
        "https://github.com/watchtowrlabs/watchTowr-vs-Fortiweb-AuthBypass",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-64446"
    ]
}