Vulnerability Intelligence Report
Fortinet FortiWeb Path Traversal Vulnerability
CVE-2025-64446
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.4
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:89.53%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-23 ↗Escalation of privilege
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Fortinet | FortiWeb | 8.0.0 <= 8.0.1 (affected), 7.6.0 <= 7.6.4 (affected), 7.4.0 <= 7.4.9 (affected), 7.2.0 <= 7.2.11 (affected), 7.0.0 <= 7.0.11 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
89.526%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Fortinet, Inc. · Vendor · USA |
| Reserved | 2025-11-04T14:26:34 |
| Published | 2025-11-14T15:50:52 |
| Last Updated | 2026-02-26T16:56:56 |
Community Chatter & Buzz