Security researchers are warning of two critical vulnerabilities in Fortinet's FortiWeb appliances, now tracked under CVE-2025-64446 and actively exploited.
See also: Fortinet FortiWeb: Exploit released for critical vulnerability

According to findings published by watchTowr, one vulnerability allows unauthenticated attackers to access internal CGI points via a relative path, while the other authentication bypass issue allows them to impersonate any administrator by exploiting the “HTTP_CGIINFO” header. Even more concerning is the apparent exploitation of the vulnerability for weeks before Fortinet’s announcement on November 14, making the vulnerability a zero-day.
Fortinet reportedly pushed out silent updates for the bug via v8.0.2 after reports of exploits emerged. “ Over the past few days, multiple security firms, CERTs, and individuals have raised the alarm about the silently updated vulnerability being actively exploited, ” VulnCheck ’s Caitlin Condon said in a blog post.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the bug to its list of Known Exploitable Vulnerabilities (KEV), directing all federal civil agencies to update the bug by November 21. The first phase of the attack chain begins with a relative path to the FortiWeb GUI/API handler. The Picus researchers explain that requests under the path “ api/v2.0/ ” can be manipulated using sequences such as “ ../../../../../cgi-bin/fwbcgi “, thereby redirecting the call to the internal legacy CGI component instead of the intended API point.
See also: Vulnerability in FortiPAM and FortiSwitch Manager bypasses verification process

Essentially, the device's Apache configuration forwards the crafted request to "fwbcgi", bypassing expected protections. Once the attacker reaches the CGI backend, he exploits a second design flaw - the cgi_auth() blindly processes a client-supplied "HTTP_CGIINFO" header. The JSON fields in the header accept username, profname, vdom , and loginname without proper checks, allowing an unauthenticated attacker to impersonate any administrator account and gain full administrator privileges.
Combined, these steps allow for full remote code execution without credentials. The relative path opens the door, and header forgery sets the attack in motion. Fortinet gave the flaw a severity rating of 9.1 out of 10, while Picus researchers believe it should be 9.8.
While Fortinet officially published an advisory for CVE-2025-64446 on November 14, 2025, the vendor's previous release note made no mention of the vulnerability or the fix, leading to criticism that the update was applied silently. VulnCheck had reported nearly 300 instances of FortiWeb facing the internet via Shodan and a wider ~2700 via FOFA, all potentially vulnerable.
See also: Coordinated attack on Cisco, Fortinet and Palo Alto Networks devices

Affected versions include 7.0.0 to 7.0.11, 7.2.0 to 7.2.11, 7.4.0 to 7.4.9, 7.6.0 to 7.6.4 , and 8.0.0 to 8.0.1. The fixes apply to versions 7.0.12, 7.2.12, 7.4.10, 7.6.5 , and 8.0.2. Fortinet recommends disabling HTTP or HTTPS for internet-facing interfaces for customers who cannot upgrade immediately.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
