๐Ÿ”ด CVE-2025-25257

Critical SQL injection vulnerability in Fortinet FortiWeb WAF allowing unauthenticated attackers to execute arbitrary SQL and code via crafted HTTP/HTTPS requests. CISA has confirmed active exploitation in the wild with public PoC available.

โ† Back to Overview
HIGH_RISK
Risk Level
T1190
MITRE Technique
9.6
CVSS Score
NETWORK
Attack Vector
VERY_HIGH
Deployment Risk

๐Ÿ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-07-17

Added to CISA KEV: 2025-07-18 1 DAY BETWEEN CVE AND KEV

๐ŸŽฏ Recommendations:

๐Ÿ” Web Intelligence

Key Sources: