EXPOSURES › CVE-2025-25257
CVE-2025-25257
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
rceexploited-in-wildunpatched
FortiWeb SQL Injection allowed unauthenticated attackers to execute SQL code.
Fortinet's FortiWeb suffered a SQL injection vulnerability, enabling attackers to execute unauthorized SQL commands through crafted HTTP or HTTPs requests without authentication, posing a significant security risk.
Shame score — Unpatched vulnerability actively exploited by attackers.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.