CVE-2025-64446
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
- Affected products
- Fortiweb
- Fortinet Fortiweb
- < 7.0.12, 7.2.12, 7.4.10, 7.6.5, 8.0.2
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 91.8% (100th percentile)
- Weakness
- CWE-23
- NVD status
- Analyzed
- Published
- 2025-11-14
Fix
Upgrade to FortiWeb version 8.0.2 or above Upgrade to FortiWeb version 7.6.5 or above Upgrade to FortiWeb version 7.4.10 or above Upgrade to FortiWeb version 7.2.12 or above Upgrade to FortiWeb version 7.0.12 or above
CVE-2025-64446 at NVD
17 known exploits for CVE-2025-64446
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Relative Path Traversal in Fortinet Fortiweb
Exploit for OS Command Injection in Fortinet Fortiweb
π FortiWeb 8.0.1 Authentication Bypass / Code Execution
π FortiWeb 8.0.1 Remote Code Execution
FortiWeb 8.0.2 - Remote Code Execution
Fortinet FortiWeb v8.0.1 - Auth Bypass
Exploit for Relative Path Traversal in Fortinet Fortiweb
Exploit for OS Command Injection in Fortinet Fortiweb
Exploit for OS Command Injection in Fortinet Fortiweb
π FortiWeb 8.0.1 Authentication Bypass
Fortinet FortiWeb unauthenticated RCE
π Fortinet FortiWeb Unauthenticated Remote Code Execution
Exploit for Relative Path Traversal in Fortinet Fortiweb
π Fortinet FortiWeb 8.0.0 Authentication Bypass
Exploit for CVE-2025-58034
Exploit for Relative Path Traversal in Fortinet Fortiweb
Fortinet FortiWeb create new local admin