A new security vulnerability in FortiWeb has been reported to have been exploited in the wild, according to Fortinet.
Tracked as CVE-2025-58034, the medium-severity vulnerability has a CVSS score of 6.7 out of a possible 10.0.
According to a Tuesday advisory from the company, an authenticated attacker may be able to execute unauthorized code on the underlying system through crafted HTTP requests or CLI commands due to an Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability [CWE-78] in FortiWeb.
To put it another way, in order for an attack to be effective, the attacker must first identify himself using another method before chaining it with CVE-2025-58034 to carry out arbitrary operating system operations.
It has been addressed in the following versions –
- FortiWeb 8.0.0 through 8.0.1 (Upgrade to 8.0.2 or above)
- FortiWeb 7.6.0 through 7.6.5 (Upgrade to 7.6.6 or above)
- FortiWeb 7.4.0 through 7.4.10 (Upgrade to 7.4.11 or above)
- FortiWeb 7.2.0 through 7.2.11 (Upgrade to 7.2.12 or above)
- FortiWeb 7.0.0 through 7.0.11 (Upgrade to 7.0.12 or above)
In accordance with its responsible disclosure policy, the business acknowledged Trend Micro researcher read more about Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited in the Wild.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
