Fortinet FortiWeb is a Web Application Firewall that protects web applications and APIs from attacks. Its Fabric Connector integrates FortiWeb with the broader Fortinet security ecosystem. CVE-2025-25257 is a critical SQL injection vulnerability in this connector that allows an unauthenticated remote attacker to execute code on the device, with the risk of a complete system compromise.
| Product | Cisco ISE |
| Date | 2025-07-22 10:02:04 |
Technical Summary
The vulnerability resides in the get_fabric_user_by_token function, which improperly handles the Authorization header, allowing for SQL injection via the /api/fabric/device/status endpoint without the need for authentication. By exploiting this flaw, an attacker can write malicious files as the root user using the MySQL SELECT INTO OUTFILE command, placing a specially crafted Python .pth file that triggers remote code execution through a Python CGI script (ml-draw.py). This multi-step attack effectively disables the protection offered by the WAF and compromises the entire system. The flaw is being actively exploited in real-world environments.
Recommendations
- Immediately apply the update to FortiWeb versions 7.6.4, 7.4.8, 7.2.11, 7.0.11 or later.
- Temporarily disable the HTTP/HTTPS administration interface if there is a delay in applying the patch.
- Monitor network traffic for suspicious API calls and scan for the presence of unauthorized .pth files.
- Isolate administration interfaces on secure networks, avoiding public exposure.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
