CVE-2025-64446
CRITICAL KEV RANSOMWARE NUCLEIFortinet FortiWeb unauthenticated RCE
Title source: metasploitDescription
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
Exploits (17)
nomisec
WORKING POC
14 stars
by soltanali0 · remote
https://github.com/soltanali0/CVE-2025-64446-Exploit
nomisec
WORKING POC
10 stars
by lincemorado97 · poc
https://github.com/lincemorado97/CVE-2025-64446_CVE-2025-58034
nomisec
WORKING POC
10 stars
by sxyrxyy · remote
https://github.com/sxyrxyy/CVE-2025-64446-FortiWeb-CGI-Bypass-PoC
nomisec
WRITEUP
6 stars
by fevar54 · infoleak
https://github.com/fevar54/CVE-2025-64446-PoC---FortiWeb-Path-Traversal
github
SUSPICIOUS
2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-64446
nomisec
WORKING POC
1 stars
by AN5I · remote
https://github.com/AN5I/cve-2025-64446-fortiweb-exploit
nomisec
WRITEUP
by BaoSec · poc
https://github.com/BaoSec/CVE-2025-64446-CVE-2025-58034-Research-and-Analysis
metasploit
WORKING POC
by Defused, sfewer-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/fortinet_fortiweb_create_admin.rb
Nuclei Templates (1)
FortiWeb - Authentication Bypass
CRITICALVERIFIEDby DhiyaneshDk,watchTowr,rapid7,defusedcyber
Shodan:
title:"FortiWeb - "
Scores
CVSS v3
9.8
EPSS
0.8901
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2025-11-14
VulnCheck KEV
2025-10-06
ENISA EUVD
EUVD-2025-197613
Ransomware Use
Confirmed
Classification
CWE
CWE-23
Status
published
Affected Products (1)
fortinet/fortiweb
< 7.0.12
Timeline
Published
Nov 14, 2025
KEV Added
Nov 14, 2025
Tracked Since
Feb 18, 2026