CVE-2025-52970
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.
- Affected products
- Fortiweb
- Fortinet Fortiweb
- < 7.0.11, 7.2.11, 7.4.8, 7.6.4
- Fix
- Available
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 9.8% (95th percentile)
- Weakness
- CWE-233
- NVD status
- Analyzed
- Published
- 2025-08-12
Fix
Upgrade to FortiWeb version 8.0.0 or above Upgrade to FortiWeb version 7.6.4 or above Upgrade to FortiWeb version 7.4.8 or above Upgrade to FortiWeb version 7.2.11 or above Upgrade to FortiWeb version 7.0.11 or above
CVE-2025-52970 at NVD
3 known exploits for CVE-2025-52970
Proof-of-concept code and exploit modules indexed by Sploitus