CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: Aug 8, 2025
Description
Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
EPSS — Exploit Probability
28.1%
Higher than 96.4% of all CVEs
Required Action
https://fortiguard.fortinet.com/psirt/FG-IR-25-151 ; https://nvd.nist.gov/vuln/detail/CVE-2025-25257
Risk Assessment
ELEVATEDIn CISA KEV
Details
- Severity
- High
- EPSS
- 28.1%
- CISA KEV
- Yes
- Ransomware
- Unknown
- Articles
- 0
Timeline
Published
Jul 18, 2025
Added to KEV
Jul 18, 2025
Remediation Due
Aug 8, 2025