← Back to browse · API

CVE-2025-25257

Severity
CRITICAL
CVSS
9.6
EPSS
0.9671
Risk score
58.85
CISA KEV
Yes
PoC
No
Published
2025-07-17
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-21785, GHSA-MJ4R-RPWM-GG33
Products
Fortinet:FortiWeb, Fortinet:FortiWeb 7.0.0 ≤7.0.10, Fortinet:FortiWeb 7.2.0 ≤7.2.10, Fortinet:FortiWeb 7.4.0 ≤7.4.7, Fortinet:FortiWeb 7.6.0 ≤7.6.3
Sources
cisa.gov CVE-2025-25257
euvd EUVD-2025-21785

Description

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

References