Fortinet FortiWeb is a Web Application Firewall (WAF) solution deployed at the network perimeter to protect critical web applications from a wide range of cyberattacks. Due to its strategic position, it is often exposed to the Internet, becoming a high-value target for threat actors seeking to compromise an organization’s perimeter security.
This vulnerability presents a critical risk, as it allows an unauthenticated remote attacker to gain full administrative control over the FortiWeb device. A successful exploit leads to complete system compromise, allowing the attacker to disable security protections, intercept sensitive data, and use the device as an entry point for further attacks on the internal network.
Although there are currently no public reports of active exploitation of CVE-2025-64446, a public exploit is available. This significantly increases the likelihood of attack, as the barrier to entry for potential threats is very low. All organizations using the affected versions, particularly those with management interfaces exposed to the Internet, are at immediate risk and must act urgently.
| Product | Fortinet FortiWeb |
| Date | 2025-12-06 12:22:11 |
Technical Summary
The root cause of this vulnerability is a CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’). The FortiWeb management interface fails to properly sanitize user-supplied input within HTTP and HTTPS requests, allowing an attacker to use path traversal sequences (e.g., ../) to escape the restricted web root directory.
The attack chain can be summarized as follows:
- An unauthenticated attacker sends a specially crafted HTTP/S request to an exposed FortiWeb device.
- The request targets an unspecified API endpoint and includes path traversal sequences in a parameter.
- The underlying software does not neutralize these sequences, granting the attacker read/write access to arbitrary files on the filesystem.
- By accessing and executing administrative scripts or binaries at the system level, the attacker achieves remote code execution with the privileges of the web server process, which operates as an administrator.
Affected Versions:
- FortiWeb 8.0: versions 8.0.0 to 8.0.1
- FortiWeb 7.6: versions 7.6.0 to 7.6.4
- FortiWeb 7.4: versions 7.4.0 to 7.4.9
- FortiWeb 7.2: versions 7.2.0 to 7.2.11
- FortiWeb 7.0: versions 7.0.0 to 7.0.11
Fortinet has released patches for all affected branches. A successful exploit allows an attacker to take complete control of the device, turning it into a hostile agent on the network perimeter.
Recommendations
- Apply patches immediately: Update all affected FortiWeb devices to the latest patched version provided by Fortinet for your release line.
- Mitigation measures: As a temporary measure, if patching is not immediately possible, restrict all access to the FortiWeb management interface to a dedicated, secure internal network. Do not expose the management interface to the Internet. Use Access Control Lists (ACLs) on upstream devices to enforce this limitation.
- Hunting and monitoring:
- Check the FortiWeb device’s web access logs for requests containing path traversal sequences such as
../,..%2f,%2e%2e/, and related encoded variants. - Monitor for any anomalous outbound network connections originating from the FortiWeb device, which could indicate a successful compromise and communication with a command and control (C2) server.
- Look for the creation of unexpected files or active processes with administrative privileges on the device.
- Check the FortiWeb device’s web access logs for requests containing path traversal sequences such as
- Incident Response: If a compromise is suspected, immediately isolate the affected FortiWeb device from the network to prevent lateral movement. Preserve all logs, disk images, and configuration files for forensic analysis. Assume that all traffic that passed through the WAF may have been compromised and initiate a thorough incident investigation.
- Defense in depth: Ensure network segmentation is implemented to limit the impact of a compromised perimeter device. Regularly back up appliance configurations to facilitate rapid recovery in the event of a security incident.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
