Tag: Fortinet FortiWeb

Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin Accounts
News

Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin Accounts

Cybersecurity researchers are sounding the alert about an authentication bypass vulnerability in Fortinet Fortiweb WAF that could allow an attacker to take over admin accounts and completely compromise a device. According to Benjamin Harris, CEO and founder of watchTowr, the watchTowr team is observing active and indiscriminate exploitation in the wild of what seems to be a silently patched vulnerability in Fortinet's FortiWeb product. In version 8.0.2, the vulnerability was patched. It enables attackers to execute actions as a privileged user, with real-world exploitation centering on the addition of a new administrator account as a fundamental persistence method for the attackers. The cybersecurity firm stated that it managed to successfully replicate the vulnerability and deve...
New Fortinet FortiWeb hacks likely linked to public RCE exploits
News

New Fortinet FortiWeb hacks likely linked to public RCE exploits

It is thought that public exploits for a recently patched remote code execution (RCE) vulnerability identified as CVE-2025-25257 were used to hack several Fortinet FortiWeb instances that were recently infected with web shells. The Shadowserver Foundation, a threat monitoring platform, reported the exploitation activity after observing 85 infections on July 14 and 77 the next day. According to the researchers, the CVE-2025-25257 vulnerability is thought to have compromised these Fortinet FortiWeb instances. The pre-authenticated RCE via SQL injection (SQLi) vulnerability CVE-2025-25257 affects FortiWeb versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.4.0 through 7.4.7, and 7.0.0 through 7.0.10. On July 8, 2025, Fortinet published patches advising users to update to all branch...