CVE-2025-64446

CRITICAL KEV RANSOMWARE NUCLEI

Fortinet FortiWeb unauthenticated RCE

Title source: metasploit

Description

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Exploits (17)

nomisec SCANNER 28 stars
by sensepost · poc
https://github.com/sensepost/CVE-2025-64446
nomisec WORKING POC 14 stars
by soltanali0 · remote
https://github.com/soltanali0/CVE-2025-64446-Exploit
nomisec WORKING POC 10 stars
by lincemorado97 · poc
https://github.com/lincemorado97/CVE-2025-64446_CVE-2025-58034
nomisec WORKING POC 10 stars
by sxyrxyy · remote
https://github.com/sxyrxyy/CVE-2025-64446-FortiWeb-CGI-Bypass-PoC
nomisec WRITEUP 6 stars
by fevar54 · infoleak
https://github.com/fevar54/CVE-2025-64446-PoC---FortiWeb-Path-Traversal
nomisec WORKING POC 4 stars
by verylazytech · remote
https://github.com/verylazytech/CVE-2025-64446
github SUSPICIOUS 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-64446
nomisec WORKING POC 1 stars
by AN5I · remote
https://github.com/AN5I/cve-2025-64446-fortiweb-exploit
nomisec WORKING POC
by D3crypT0r · remote
https://github.com/D3crypT0r/CVE-2025-64446
nomisec STUB
by Death112233 · poc
https://github.com/Death112233/CVE-2025-64446-
nomisec WRITEUP
by lequoca · poc
https://github.com/lequoca/fortinet-fortiweb-cve-2025-64446-58034
nomisec WRITEUP
by BaoSec · poc
https://github.com/BaoSec/CVE-2025-64446-CVE-2025-58034-Research-and-Analysis
nomisec WRITEUP
by BaoSec · poc
https://github.com/BaoSec/FortiWeb-CVE
metasploit WORKING POC
by Defused, sfewer-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/fortinet_fortiweb_create_admin.rb
vulncheck_xdb WORKING POC
remote
https://github.com/watchtowrlabs/watchTowr-vs-Fortiweb-AuthBypass
vulncheck_xdb WORKING POC
remote
https://github.com/lincemorado97/CVE-2025-64446

Nuclei Templates (1)

FortiWeb - Authentication Bypass
CRITICALVERIFIEDby DhiyaneshDk,watchTowr,rapid7,defusedcyber
Shodan: title:"FortiWeb - "

Scores

CVSS v3 9.8
EPSS 0.8901
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2025-11-14
VulnCheck KEV 2025-10-06
ENISA EUVD EUVD-2025-197613
Ransomware Use Confirmed

Classification

CWE
CWE-23
Status published

Affected Products (1)

fortinet/fortiweb < 7.0.12

Timeline

Published Nov 14, 2025
KEV Added Nov 14, 2025
Tracked Since Feb 18, 2026