FortiWeb: Path confusion vulnerability in GUI / CVSS:9.1

Fortinet published information about a new vulnerability in FortiWeb. Affected devices must have specific firmware patches and management interfaces accessible via the WAN. Patched already exist to fix the issue.


PSIRT information

https://www.fortiguard.com/psirt/FG-IR-25-910

IR NumberFG-IR-25-910
Published DateNov 14, 2025
ComponentGUI
Severity Critical
CVSSv3 Score9.1
ImpactImproper access control
CVE IDCVE-2025-64446

Affected and patched releases

VersionAffectedSolution
FortiWeb 8.08.0.0 through 8.0.1Upgrade to 8.0.2 or above
FortiWeb 7.67.6.0 through 7.6.4Upgrade to 7.6.5 or above
FortiWeb 7.47.4.0 through 7.4.9Upgrade to 7.4.10 or above
FortiWeb 7.27.2.0 through 7.2.11Upgrade to 7.2.12 or above
FortiWeb 7.07.0.0 through 7.0.11Upgrade to 7.0.12 or above

If you are using an affected release, please upgrade asap or remove management access via HTTP/HTTPS from the Internet.

Loading

Leave a Reply

Your email address will not be published. Required fields are marked *