Friday, September 11, 2026

FortiWeb SQL Injection Vulnerability Allows Attackers to Execute Malicious SQL Commands

A critical security vulnerability has been discovered in Fortinet’s FortiWeb web application firewall that allows unauthenticated attackers to execute malicious SQL commands through the device’s graphical user interface.

The flaw, designated as CVE-2025-25257, poses significant risks to organizations relying on FortiWeb for web application protection.

Vulnerability Details

The vulnerability stems from improper neutralization of special elements used in SQL commands, classified as CWE-89 in the Common Weakness Enumeration database.

FieldValue
CVE IDCVE-2025-25257
SeverityCritical
CVSS v3 Score9.6
CWE ClassificationCWE-89 (SQL Injection)

Attackers can exploit this flaw by sending specially crafted HTTP or HTTPS requests to the FortiWeb management interface, enabling them to execute unauthorized SQL code without requiring authentication credentials.

Fortinet has assigned this vulnerability a Critical severity rating with a CVSS v3 score of 9.6, indicating the potential for complete system compromise.

The high severity reflects the vulnerability’s network accessibility, lack of authentication requirements, and potential for full confidentiality, integrity, and availability impact.

Affected Versions and Solutions

The vulnerability affects multiple FortiWeb versions across four major branches:

Version BranchAffected VersionsSolution
FortiWeb 7.67.6.0 through 7.6.3Upgrade to 7.6.4 or above
FortiWeb 7.47.4.0 through 7.4.7Upgrade to 7.4.8 or above
FortiWeb 7.27.2.0 through 7.2.10Upgrade to 7.2.11 or above
FortiWeb 7.07.0.0 through 7.0.10Upgrade to 7.0.11 or above

Organizations using affected FortiWeb versions should prioritize immediate patching to prevent potential exploitation.

The vulnerability’s unauthenticated nature means attackers can exploit it remotely without needing valid credentials, making it particularly dangerous.

For organizations unable to immediately apply patches, Fortinet recommends disabling the HTTP/HTTPS administrative interface as a temporary workaround.

However, this mitigation may significantly impact administrative operations and should be considered a short-term measure only.

The vulnerability was discovered by Kentaro Kawane from GMO Cybersecurity by Ierae through responsible disclosure practices.

Fortinet acknowledged the researcher’s contribution and coordinated the disclosure timeline appropriately.

The vulnerability was initially published on July 8, 2025, with the internal reference number FG-IR-25-151.

The affected component is the GUI interface, and the potential impact includes the execution of unauthorized code or commands.

This vulnerability highlights the critical importance of securing management interfaces for security appliances.

When web application firewalls themselves become vulnerable to the same attacks they’re designed to prevent, the irony underscores the need for robust secure development practices across all security products.

Stay Updated on Daily Cybersecurity News . Follow us on Google NewsLinkedIn, and X.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News