Multiple Fortinet FortiWeb recently infected with web shells are believed to have been compromised via public exploits for a recently patched remote code execution (RCE) vulnerability, with the identifier CVE-2025-25257.
See also: Fortinet and Ivanti patch high-severity vulnerabilities

News of this exploit activity comes from threat monitoring platform The Shadowserver Foundation , which detected 85 infections on July 14th and 77 the following day.
Researchers report that the FortiWeb installations in question are believed to have been compromised via the CVE-2025-25257 vulnerability. This is a critical unauthenticated remote code execution vulnerability based on SQL injection that affects FortiWeb versions 7.6.0 to 7.6.3, 7.4.0 to 7.4.7, and 7.0.0 to 7.0.10.
Fortinet released security updates on July 8, 2025, urging users to upgrade to FortiWeb versions 7.6.4, 7.4.8, 7.2.11 or 7.0.11 and later versions of each branch.
Exploitation of the vulnerability involves executing SQL injection via modified Authorization fields in HTTP requests sent to /api/fabric/device/status , resulting in the creation of a malicious .pth file within the Python site-packages folder
Then, a legitimate FortiWeb CGI script ( /cgi-bin/ml-draw.py ) is remotely accessed , which triggers the execution of the malicious code located in the .pth file, leading to remote code execution on the device.
See also: FortiVoice: Fortinet fixes critical zero-day vulnerability
During the period of the initial report, there was no evidence of active exploitation on the internet. However, the release of public exploit tools made the immediate application of patches by system administrators imperative.

Today's confirmation of an active exploit from The Shadowserver Foundation serves as a wake-up call for those who haven't yet installed the latest software updates on their devices. According to the threat analysis organization, 223 FortiWeb management interfaces were still exposed as of yesterday, although there is no way to determine which software version they are using.
From the compromised systems, the majority (40) are located in the United States, followed by the Netherlands (5), Singapore (4) and the United Kingdom (4).
FortiWeb is a Web Application Firewall (WAF) used by large enterprises, government organizations, and managed security service to detect and block unwanted HTTP traffic.
If an immediate upgrade to a secure version is not feasible, it is recommended to disable the administrative HTTP/HTTPS interface to limit access to the vulnerable endpoint (/api/fabric/device/status).
See also: Over 16,000 Fortinet devices contain symlink backdoor
On a broader level, the incident highlights the importance of continuous threat monitoring,vulnerability management, and timely implementation of security updates to critical infrastructure.
Source: bleepingcomputer
