Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Please upgrade to FortiWeb version 7.6.4 or above Please upgrade to FortiWeb version 7.4.9 or above
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24456 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands. |
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-253 |
|
Fri, 15 Aug 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* |
Thu, 14 Aug 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortiweb |
|
| Vendors & Products |
Fortinet
Fortinet fortiweb |
|
| Metrics |
ssvc
|
Tue, 12 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-02-26T17:48:57.003Z
Reserved: 2025-05-12T13:58:15.236Z
Link: CVE-2025-47857
Updated: 2025-08-13T14:13:38.730Z
Status : Analyzed
Published: 2025-08-12T19:15:29.997
Modified: 2025-08-15T12:25:37.050
Link: CVE-2025-47857
No data.
OpenCVE Enrichment
Updated: 2025-08-13T21:47:44Z
EUVD