CVE-2025-25254: Fortinet FortiWeb
High severity, CVSS 7.2. EPSS: 17.1% chance of exploitation in the next 30 days.
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all versions, 7.0 all versions endpoint may allow an authenticated admin to access and modify the filesystem via crafted requests.
Affected products
- Fortinet FortiWeb: from 7.0.0, before 7.4.7 (fixed in 7.4.7); from 7.6.0, before 7.6.3 (fixed in 7.6.3)
Published 2025-04-08. Last modified 2026-06-17.