News

Patch immediately: CVE-2025-25257 PoC enables remote code execution on Fortinet FortiWeb

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2025-07-13 18:10:00 UTC

PoC exploits released for critical Fortinet FortiWeb flaw allowing pre-auth RCE. Fortinet urges users to patch. Proof-of-concept (PoC) exploits for CVE-2025-25257 in Fortinet FortiWeb (CVSS 9.8) enable pre-auth RCE on vulnerable servers. The flaw is a SQL inj…

Patch immediately: CVE-2025-25257 PoC enables remote code execution on Fortinet FortiWeb Proof-of-concept (PoC) exploits for CVE-2025-25257 in Fortinet FortiWeb (CVSS 9.8) enable pre-auth RCE on vul… [+2666 chars]