← Back to browse · API

CVE-2025-58034

Severity
MEDIUM
CVSS
6.7
EPSS
0.5558
Risk score
71.25
CISA KEV
Yes
PoC
No
Published
2025-11-18
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-198020, GHSA-47CR-8W72-GGMC
Products
Fortinet:FortiWeb, Fortinet:FortiWeb 7.0.2 ≤7.0.11, Fortinet:FortiWeb 7.2.0 ≤7.2.11, Fortinet:FortiWeb 7.4.0 ≤7.4.8, Fortinet:FortiWeb 7.6.0 ≤7.6.4
Sources
cisa.gov CVE-2025-58034
euvd EUVD-2025-198020

Description

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

References