HomeSecurityNew Fortinet FortiWeb breaches linked to public RCE exploits

New Fortinet FortiWeb breaches linked to public RCE exploits

Multiple Fortinet FortiWeb recently infected with web shells are believed to have been compromised via public exploits for a recently patched remote code execution (RCE) vulnerability, with the identifier CVE-2025-25257.

See also: Fortinet and Ivanti patch high-severity vulnerabilities

FortiWeb exploits

News of this exploit activity comes from threat monitoring platform The Shadowserver Foundation , which detected 85 infections on July 14th and 77 the following day.

Researchers report that the FortiWeb installations in question are believed to have been compromised via the CVE-2025-25257 vulnerability. This is a critical unauthenticated remote code execution vulnerability based on SQL injection that affects FortiWeb versions 7.6.0 to 7.6.3, 7.4.0 to 7.4.7, and 7.0.0 to 7.0.10.

Fortinet released security updates on July 8, 2025, urging users to upgrade to FortiWeb versions 7.6.4, 7.4.8, 7.2.11 or 7.0.11 and later versions of each branch.

Exploitation of the vulnerability involves executing SQL injection via modified Authorization fields in HTTP requests sent to /api/fabric/device/status , resulting in the creation of a malicious .pth file within the Python site-packages folder

Then, a legitimate FortiWeb CGI script ( /cgi-bin/ml-draw.py ) is remotely accessed , which triggers the execution of the malicious code located in the .pth file, leading to remote code execution on the device.

See also: FortiVoice: Fortinet fixes critical zero-day vulnerability

During the period of the initial report, there was no evidence of active exploitation on the internet. However, the release of public exploit tools made the immediate application of patches by system administrators imperative.

New Fortinet FortiWeb breaches linked to public RCE exploits
New Fortinet FortiWeb breaches linked to public RCE exploits

Today's confirmation of an active exploit from The Shadowserver Foundation serves as a wake-up call for those who haven't yet installed the latest software updates on their devices. According to the threat analysis organization, 223 FortiWeb management interfaces were still exposed as of yesterday, although there is no way to determine which software version they are using.

From the compromised systems, the majority (40) are located in the United States, followed by the Netherlands (5), Singapore (4) and the United Kingdom (4).

FortiWeb is a Web Application Firewall (WAF) used by large enterprises, government organizations, and managed security service to detect and block unwanted HTTP traffic.

If an immediate upgrade to a secure version is not feasible, it is recommended to disable the administrative HTTP/HTTPS interface to limit access to the vulnerable endpoint (/api/fabric/device/status).

See also: Over 16,000 Fortinet devices contain symlink backdoor

On a broader level, the incident highlights the importance of continuous threat monitoring,vulnerability management, and timely implementation of security updates to critical infrastructure.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS