CVE-2025-25257 – Unauthenticated Remote Code Execution in Fortinet FortiWeb

ISGroup Cybersecurity

Fortinet FortiWeb is a Web Application Firewall that protects web applications and APIs from attacks. Its Fabric Connector integrates FortiWeb with the broader Fortinet security ecosystem. CVE-2025-25257 is a critical SQL injection vulnerability in this connector that allows an unauthenticated remote attacker to execute code on the device, with the risk of a complete system compromise.

ProductCisco ISE
Date2025-07-22 10:02:04

Technical Summary

The vulnerability resides in the get_fabric_user_by_token function, which improperly handles the Authorization header, allowing for SQL injection via the /api/fabric/device/status endpoint without the need for authentication. By exploiting this flaw, an attacker can write malicious files as the root user using the MySQL SELECT INTO OUTFILE command, placing a specially crafted Python .pth file that triggers remote code execution through a Python CGI script (ml-draw.py). This multi-step attack effectively disables the protection offered by the WAF and compromises the entire system. The flaw is being actively exploited in real-world environments.

Recommendations

  • Immediately apply the update to FortiWeb versions 7.6.4, 7.4.8, 7.2.11, 7.0.11 or later.
  • Temporarily disable the HTTP/HTTPS administration interface if there is a delay in applying the patch.
  • Monitor network traffic for suspicious API calls and scan for the presence of unauthorized .pth files.
  • Isolate administration interfaces on secure networks, avoiding public exposure.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert