PT-2025-46973 · Fortinet · Fortiweb
CVE-2025-64446
·
Published
2025-11-14
·
Updated
2026-09-04
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FortiWeb versions 8.0.0 through 8.0.1
FortiWeb versions 7.6.0 through 7.6.4
FortiWeb versions 7.4.0 through 7.4.9
FortiWeb versions 7.2.0 through 7.2.11
FortiWeb versions 7.0.0 through 7.0.11
Description
A relative path traversal issue exists in the
cgi auth() and cgi process() functions of the web application firewall. This flaw allows a remote attacker to escalate privileges and execute administrative commands by sending specially crafted HTTP or HTTPS requests. The issue is triggered when the system incorrectly handles relative directory paths, specifically targeting the /cgi-bin/fwbcgi file, which manages CGI requests, authentication, and administrative command execution. An example of a vulnerable endpoint is /api/v2.0/cmdb/system/admin/../../../../../cgi-bin/fwbcgi.Recommendations
Update FortiWeb versions 8.0.0 through 8.0.1 to a newer version.
Update FortiWeb versions 7.6.0 through 7.6.4 to a newer version.
Update FortiWeb versions 7.4.0 through 7.4.9 to a newer version.
Update FortiWeb versions 7.2.0 through 7.2.11 to a newer version.
Update FortiWeb versions 7.0.0 through 7.0.11 to a newer version.
Implement WAF/IDS blocking rules for requests to
/api/v.. that contain directory traversal sequences such as ../.
Restrict external network access to the /fwbcgi file.
Perform a review of recently created system users to identify unauthorized administrative accounts.Exploit
Fix
DoS
LPE
RCE
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortiweb