CVE-2025-64446

● Known-exploited CRITICAL ⚠ Exploit

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7...

Affects 1 product across 1 vendor.

CVSS 3.19.8
EPSS91.8%
Percentile100th
PatchPatched
Known-exploited since2025-11-14
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-23: CWE-23
Related Attack Patterns (CAPEC)
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-23
CAPEC-139 Relative Path Traversal
via CWE-23

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical relative path traversal vulnerability exists in multiple versions of Fortinet FortiWeb, allowing remote attackers to execute administrative commands on the system via crafted HTTP or HTTPS requests. This vulnerability has a high exploitation likelihood due to the availability of public proof-of-concept (PoC) code and active exploits.

BSID: BS-2025-GLOBAL-160706-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-64446?
A critical relative path traversal vulnerability exists in multiple versions of Fortinet FortiWeb, allowing remote attackers to execute administrative commands on the system via crafted HTTP or HTTPS requests. This vulnerability has a high exploitation likelihood due to the availability of public proof-of-concept (PoC) code and active exploits.
What is the CVSS score for CVE-2025-64446?
CVE-2025-64446 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 91.8%.
Is CVE-2025-64446 actively exploited?
Yes. CVE-2025-64446 is in the CISA known-exploited catalog (added 2025-11-14). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2025-64446?
Priority: IMMEDIATE. Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-25-910 PSIRT: [email protected]
What systems are affected by CVE-2025-64446?
CVE-2025-64446 affects: Fortinet.
What NERC-CIP standard applies to CVE-2025-64446?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 as it allows unauthorized access to the system, which could compromise the security of the control system and its data.
What IEC 62443 requirement maps to CVE-2025-64446?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited to gain unauthorized access to the system, which is a critical security concern for industrial control systems.
Vulnerability Details
CVE IDCVE-2025-64446
BSIDBS-2025-GLOBAL-160706-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2025-11-14
Last Modified2025-11-21
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited by sending specially crafted HTTP or HTTPS requests to the affected FortiWeb appliances. The attacker can leverage this to traverse directories and potentially execute arbitrary commands with administrative privileges, leading to full system compromise.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductAffected Versions
Fortinet Fortiweb ≥ 7.0.0, < 7.0.12 ≥ 7.2.0, < 7.2.12 ≥ 7.4.0, < 7.4.10 ≥ 7.6.0, < 7.6.5 ≥ 8.0.0, < 8.0.2
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 325 Days
CISA known-exploited● Active Exploitation Confirmed (added 2025-11-14)
Public Exploit⚠ Available — Reference
PoC CodeNot confirmed
● Compensating Controls — AI-drafted, review before deploying MEDIUM CONFIDENCE

Implement strict input validation and sanitization for all HTTP and HTTPS requests to prevent directory traversal attacks. Consider deploying a web application firewall (WAF) to filter out malicious requests.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. A network rule is only drafted when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 as it allows unauthorized access to the system, which could compromise the security of the control system and its data.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited to gain unauthorized access to the system, which is a critical security concern for industrial control systems.

Drafted by AI and not validated for your network. Test in an isolated environment before any production deployment. Compensating control only - does not replace vendor patch.

AI Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash913a3152729b6e88f27bc5ae238fbfc5f5f7c67e21b2aebecef03efebac56eac770e340b94294c8e7d60c93f52d7c4e00d764fe9f43679a4d78f9e10cef6fcb5
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2026-26084 9.9 A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 throug... CVE-2025-59718 9.8 A improper verification of cryptographic signature vulnerability in Fortinet ... CVE-2017-17539 9.8 The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier a... CVE-2018-13379 9.8 An Improper Limitation of a Pathname to a Restricted Directory ("Path Travers...
View all Fortinet CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2025-64446 is on the CISA known-exploited list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.

Create a free account →