CVE-2025-27759

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and before 7.0.10 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI commands
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

14 Aug 2025, 01:21

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
References () https://fortiguard.fortinet.com/psirt/FG-IR-25-150 - () https://fortiguard.fortinet.com/psirt/FG-IR-25-150 - Vendor Advisory
First Time Fortinet fortiweb
Fortinet

12 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-12 19:15

Updated : 2025-08-14 01:21


NVD link : CVE-2025-27759

Mitre link : CVE-2025-27759


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')