Skip to content
COOEY

EXPOSURES › CVE-2025-64446

CVE-2025-64446

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-11-14 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-64446 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

FortiWeb RCE due to unpatched path traversal

Fortinet's FortiWeb suffered an unauthenticated RCE due to a path traversal vulnerability, allowing attackers to execute admin commands via crafted HTTP/HTTPS requests.

Shame score — Unpatched vulnerability enabling remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.