CVE-2025-64446
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7...
Affects 1 product across 1 vendor.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical relative path traversal vulnerability exists in multiple versions of Fortinet FortiWeb, allowing remote attackers to execute administrative commands on the system via crafted HTTP or HTTPS requests. This vulnerability has a high exploitation likelihood due to the availability of public proof-of-concept (PoC) code and active exploits.
BSID: BS-2025-GLOBAL-160706-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-64446?
What is the CVSS score for CVE-2025-64446?
Is CVE-2025-64446 actively exploited?
How do I remediate CVE-2025-64446?
What systems are affected by CVE-2025-64446?
What NERC-CIP standard applies to CVE-2025-64446?
What IEC 62443 requirement maps to CVE-2025-64446?
| CVE ID | CVE-2025-64446 |
|---|---|
| BSID | BS-2025-GLOBAL-160706-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2025-11-14 |
| Last Modified | 2025-11-21 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
Source: NIST NVD / MITRE CVE Database
The vulnerability can be exploited by sending specially crafted HTTP or HTTPS requests to the affected FortiWeb appliances. The attacker can leverage this to traverse directories and potentially execute arbitrary commands with administrative privileges, leading to full system compromise.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Affected Versions |
|---|---|---|
| Fortinet | Fortiweb | ≥ 7.0.0, < 7.0.12 ≥ 7.2.0, < 7.2.12 ≥ 7.4.0, < 7.4.10 ≥ 7.6.0, < 7.6.5 ≥ 8.0.0, < 8.0.2 |
| CISA known-exploited | ● Active Exploitation Confirmed (added 2025-11-14) |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
Implement strict input validation and sanitization for all HTTP and HTTPS requests to prevent directory traversal attacks. Consider deploying a web application firewall (WAF) to filter out malicious requests.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. A network rule is only drafted when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 as it allows unauthorized access to the system, which could compromise the security of the control system and its data.
This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited to gain unauthorized access to the system, which is a critical security concern for industrial control systems.
Drafted by AI and not validated for your network. Test in an isolated environment before any production deployment. Compensating control only - does not replace vendor patch.
AI Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 913a3152729b6e88f27bc5ae238fbfc5f5f7c67e21b2aebecef03efebac56eac770e340b94294c8e7d60c93f52d7c4e00d764fe9f43679a4d78f9e10cef6fcb5 |
This Vulnerability Is Being Actively Exploited
CVE-2025-64446 is on the CISA known-exploited list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.
Create a free account →