Fortinet FortiWeb Flaw Exploited in the Wild After PoC Publication

Fortinet FortiWeb Flaw Exploited in the Wild After PoC Publication

Hackers rapidly began exploiting a critical SQL injection vulnerability in Fortinet FortiWeb after proof-of-concept code was made public. This flaw allows unauthenticated remote code execution, putting thousands of devices at risk. #CVE2025-25257 #FortinetFortiWeb

Keypoints

  • The vulnerability in FortiWeb is an SQL injection flaw that can lead to remote code execution.
  • Fortinet released patches for affected versions on July 8, urging users to update immediately.
  • Attackers started exploiting the vulnerability shortly after the PoC exploit was made available.
  • Over 20,000 FortiWeb devices may be exposed to this threat, according to Censys.
  • Security organizations have observed webshells being planted on compromised instances, with numbers decreasing over time.

Read More: https://www.securityweek.com/fortinet-fortiweb-flaw-exploited-in-the-wild-after-poc-publication/