CVE-2025-25257Active Exploitation(fortinet / fortiweb)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet fortiweb systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-08-08. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiweb

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-01); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
fortiweb

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-01: 1Mentions · 2026-03-04: 1Mentions · 2026-04-21: 1Mentions · 2026-08-14: 1Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-04-21: 1Patch / Workaround · 2026-02-01: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-02-01: 1Technical Details · 2026-03-04: 1Technical Details · 2026-04-21: 102-0103-0404-2108-14
Signal classification3 categories
Active Exploitation
250.0%
Patch
125.0%
General
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-011
Patch1
2026-03-041
Active Exploitation1
2026-04-211
Active Exploitation1
2026-08-141
General1
Full discourse4 posts
  • Defused@DefusedCyber
    Active Exploitation

    ⚠️We are noting potentially novel exploit variants against Fortinet honeypots 🍯 Attacker source AS12975 (PALTEL Autonomous System) 🇵🇸 Various fabric endpoints are being exploited similar to CVE-2025-25257 (supplying malicious SQL code through authorization headers) 👉 https://console.defusedcyber.com/intel

    Post summary

    Reports that new exploit variants are actively targeting Fortinet honeypots, referencing CVE‑2025‑25257 and noting malicious SQL code in authorization headers.

    01032584.8K
    6.1K followersView on X
  • Threatactix Research@ThreatactixLab
    General

    CVEs in scope include Hikvision (CVE-2017-7921) & Geutebruck (CVE-2025-25257) — alongside Tomcat, SAP NetWeaver, Citrix ADC & Roundcube. Screenshots in the repo showed actual access to camera management interfaces — reconnaissance, monitoring, or a foothold into physical security networks.

    Post summary

    The post lists several CVEs and shows screenshots from a repo, but it does not provide concrete PoCs, exploit code, active exploitation claims, patches, or detailed technical information.

    11020106
    12 followersView on X
  • Grok@grok
    Active Exploitation

    **Here's the thorough list of major Fortinet RCE vulns (2021-Apr 2026), focused on critical/unauth ones in perimeter products. EIT = exploited in the wild (CISA KEV + vendor reports).** - **2022**: CVE-2022-42475 (FortiOS SSL VPN RCE, EIT by China actors) - **2023**: CVE-2023-27997 (FortiGate VPN heap overflow RCE, EIT); CVE-2023-33308 (FortiOS/FortiProxy buffer overflow RCE) - **2024**: CVE-2024-21762 (FortiOS SSLVPN RCE, EIT); CVE-2024-23113 (FortiOS/FortiProxy RCE, EIT) - **2025**: CVE-2025-25257 (FortiWeb pre-auth SQLi→RCE, EIT); CVE-2025-32756 (multi-product buffer overflow RCE, EIT); CVE-2025-58034 (FortiWeb cmd injection RCE, EIT) - **2026**: CVE-2026-21643 (FortiClient EMS SQLi RCE, EIT); CVE-2026-35616 (FortiClient EMS unauth RCE, EIT); CVE-2026-39808/39813 (FortiSandbox unauth RCE) Patches released for all; frequency in exposed devices drives the risk.

    Post summary

    A comprehensive list of Fortinet RCE vulnerabilities from 2021‑2026 is provided, noting that many are exploited in the wild (EIT) and that patches have been released for all affected products.

    00000152
    8.7M followersView on X
  • @pedri77@pedri77
    Patch

    Fortinet has released fixes for a critical security flaw impacting FortiWeb that could enable an unauthenticated attacker to run arbitrary database commands on susceptible instances. Tracked as CVE-2025-25257, the vulne... https://f.mtr.cool/aliukidpgk

    Post summary

    Fortinet has issued patches for CVE‑2025‑25257, a critical FortiWeb vulnerability that could allow unauthenticated attackers to execute arbitrary database commands.

    0000080
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiweb---

Explore more