Critical severity9.8CISA KEVNVD Advisory· Published Nov 14, 2025· Updated Jun 17, 2026
CVE-2025-64446
CVE-2025-64446
Description
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=7.0.0,<7.0.12
- cpe:2.3:a:fortinet:fortiweb:8.0.1:*:*:*:*:*:*:*range: 8.0.0
- (no CPE)range: 8.0.0 through 8.0.1, 7.6.0 through 7.6.4, 7.4.0 through 7.4.9, 7.2.0 through 7.2.11, 7.0.0 through 7.0.11
Patches
Vulnerability mechanics
References
2- fortiguard.fortinet.com/psirt/FG-IR-25-910nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
4- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit ReposThe Hacker News · Jul 2, 2026
- ChocoPoc malware delivered via trojanized exploits on GitHubBleepingComputer · Jul 1, 2026
- New ChocoPoC malware targets researchers via trojanized PoC exploitsBleepingComputer · Jul 1, 2026
- When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb Auth. Bypass CVE-2025-64446)watchTowr Labs · Nov 14, 2025