CVE-2025-25257
CRITICAL KEV NUCLEIFortinet FortiWeb - SQL Injection
Title source: nucleiDescription
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
Exploits (18)
exploitdb
WORKING POC
by Milad Karimi (Ex3ptionaL) · textwebappsmultiple
https://www.exploit-db.com/exploits/52473
nomisec
WORKING POC
96 stars
by watchtowrlabs · remote
https://github.com/watchtowrlabs/watchTowr-vs-FortiWeb-CVE-2025-25257
nomisec
WRITEUP
by GarethMSheldon · poc
https://github.com/GarethMSheldon/Fortinet-FortiWeb-Fabric-Connector-CVE-2025-25257-Detection
nomisec
WORKING POC
by adilburaksen · remote
https://github.com/adilburaksen/CVE-2025-25257-Exploit-Tool
Nuclei Templates (1)
Fortinet FortiWeb - SQL Injection
CRITICALVERIFIEDby watchtowr,johnk3r
Shodan:
ssl:"cn=fortiweb" || title:"FortiWeb - "
References (5)
Scores
CVSS v3
9.8
EPSS
0.2211
EPSS Percentile
95.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2025-07-18
VulnCheck KEV
2025-07-11
ENISA EUVD
EUVD-2025-21785
CWE
CWE-89
Status
published
Products (1)
fortinet/fortiweb
7.0.0 - 7.0.11
Published
Jul 17, 2025
KEV Added
Jul 18, 2025
Tracked Since
Feb 18, 2026