PT-2025-46973 · Fortinet · Fortiweb

CVE-2025-64446

·

Published

2025-11-14

·

Updated

2026-09-04

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiWeb versions 8.0.0 through 8.0.1 FortiWeb versions 7.6.0 through 7.6.4 FortiWeb versions 7.4.0 through 7.4.9 FortiWeb versions 7.2.0 through 7.2.11 FortiWeb versions 7.0.0 through 7.0.11
Description A relative path traversal issue exists in the cgi auth() and cgi process() functions of the web application firewall. This flaw allows a remote attacker to escalate privileges and execute administrative commands by sending specially crafted HTTP or HTTPS requests. The issue is triggered when the system incorrectly handles relative directory paths, specifically targeting the /cgi-bin/fwbcgi file, which manages CGI requests, authentication, and administrative command execution. An example of a vulnerable endpoint is /api/v2.0/cmdb/system/admin/../../../../../cgi-bin/fwbcgi.
Recommendations Update FortiWeb versions 8.0.0 through 8.0.1 to a newer version. Update FortiWeb versions 7.6.0 through 7.6.4 to a newer version. Update FortiWeb versions 7.4.0 through 7.4.9 to a newer version. Update FortiWeb versions 7.2.0 through 7.2.11 to a newer version. Update FortiWeb versions 7.0.0 through 7.0.11 to a newer version. Implement WAF/IDS blocking rules for requests to /api/v.. that contain directory traversal sequences such as ../. Restrict external network access to the /fwbcgi file. Perform a review of recently created system users to identify unauthorized administrative accounts.

Exploit

Fix

DoS

LPE

RCE

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14084
CVE-2025-64446

Affected Products

Fortiweb