HomeSecurityFortinet's silent update exploits serious flaw in FortiWeb

Fortinet's silent update exploits serious flaw in FortiWeb

Security researchers are warning of two critical vulnerabilities in Fortinet's FortiWeb appliances, now tracked under CVE-2025-64446 and actively exploited.

See also: Fortinet FortiWeb: Exploit released for critical vulnerability

Fortinet

According to findings published by watchTowr, one vulnerability allows unauthenticated attackers to access internal CGI points via a relative path, while the other authentication bypass issue allows them to impersonate any administrator by exploiting the “HTTP_CGIINFO” header. Even more concerning is the apparent exploitation of the vulnerability for weeks before Fortinet’s announcement on November 14, making the vulnerability a zero-day.

Fortinet reportedly pushed out silent updates for the bug via v8.0.2 after reports of exploits emerged. “ Over the past few days, multiple security firms, CERTs, and individuals have raised the alarm about the silently updated vulnerability being actively exploited, ” VulnCheck ’s Caitlin Condon said in a blog post.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the bug to its list of Known Exploitable Vulnerabilities (KEV), directing all federal civil agencies to update the bug by November 21. The first phase of the attack chain begins with a relative path to the FortiWeb GUI/API handler. The Picus researchers explain that requests under the path “ api/v2.0/ ” can be manipulated using sequences such as “ ../../../../../cgi-bin/fwbcgi “, thereby redirecting the call to the internal legacy CGI component instead of the intended API point.

See also: Vulnerability in FortiPAM and FortiSwitch Manager bypasses verification process

Fortinet's silent update exploits serious flaw in FortiWeb

Essentially, the device's Apache configuration forwards the crafted request to "fwbcgi", bypassing expected protections. Once the attacker reaches the CGI backend, he exploits a second design flaw - the cgi_auth() blindly processes a client-supplied "HTTP_CGIINFO" header. The JSON fields in the header accept username, profname, vdom , and loginname without proper checks, allowing an unauthenticated attacker to impersonate any administrator account and gain full administrator privileges.

Combined, these steps allow for full remote code execution without credentials. The relative path opens the door, and header forgery sets the attack in motion. Fortinet gave the flaw a severity rating of 9.1 out of 10, while Picus researchers believe it should be 9.8.

While Fortinet officially published an advisory for CVE-2025-64446 on November 14, 2025, the vendor's previous release note made no mention of the vulnerability or the fix, leading to criticism that the update was applied silently. VulnCheck had reported nearly 300 instances of FortiWeb facing the internet via Shodan and a wider ~2700 via FOFA, all potentially vulnerable.

See also: Coordinated attack on Cisco, Fortinet and Palo Alto Networks devices

Fortinet's silent update exploits serious flaw in FortiWeb

Affected versions include 7.0.0 to 7.0.11, 7.2.0 to 7.2.11, 7.4.0 to 7.4.9, 7.6.0 to 7.6.4 , and 8.0.0 to 8.0.1. The fixes apply to versions 7.0.12, 7.2.12, 7.4.10, 7.6.5 , and 8.0.2. Fortinet recommends disabling HTTP or HTTPS for internet-facing interfaces for customers who cannot upgrade immediately.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS