Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Aug 8, 2025

High
CISA KEV

CVE-2025-25257

FortinetFortiWeb

Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Required Action

https://fortiguard.fortinet.com/psirt/FG-IR-25-151 ; https://nvd.nist.gov/vuln/detail/CVE-2025-25257

Vulnerability Overview

Severity
High
CISA KEV
Yes
Ransomware
Unknown
Published
Jul 18, 2025
KEV Added
Jul 18, 2025
Due Date
Aug 8, 2025
Related Articles
0

Vendor

Fortinet

FortiWeb