VYPR
Unrated severityNVD Advisory· Published Sep 9, 2025· Updated Jan 14, 2026

CVE-2025-53609

CVE-2025-53609

Description

A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests.

Affected products

2
  • Fortinet/Fortiwebv52 versions
    cpe:2.3:a:fortinet:fortiweb:7.6.4:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortiweb:7.6.4:*:*:*:*:*:*:*range: 7.6.0
    • (no CPE)range: >=7.0.2 <=7.0.11, >=7.2.0 <=7.2.11, >=7.4.0 <=7.4.8, >=7.6.0 <=7.6.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.