Hackers rapidly began exploiting a critical SQL injection vulnerability in Fortinet FortiWeb after proof-of-concept code was made public. This flaw allows unauthenticated remote code execution, putting thousands of devices at risk. #CVE2025-25257 #FortinetFortiWeb
Keypoints
- The vulnerability in FortiWeb is an SQL injection flaw that can lead to remote code execution.
- Fortinet released patches for affected versions on July 8, urging users to update immediately.
- Attackers started exploiting the vulnerability shortly after the PoC exploit was made available.
- Over 20,000 FortiWeb devices may be exposed to this threat, according to Censys.
- Security organizations have observed webshells being planted on compromised instances, with numbers decreasing over time.
Read More: https://www.securityweek.com/fortinet-fortiweb-flaw-exploited-in-the-wild-after-poc-publication/