Skip to content
COOEY

EXPOSURES › CVE-2025-58034

CVE-2025-58034

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-11-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-58034 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Fortinet FortiWeb OS command injection allowed unauthorized code execution by authenticated attackers.

An authenticated attacker exploited a Fortinet FortiWeb OS command injection vulnerability, potentially allowing unauthorized code execution on the underlying system. This vulnerability was actively exploited in the wild.

Shame score — Active exploitation in the wild indicates negligence in security practices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.