CVE-2025-47857
published 2025-08-12CVE-2025-47857: A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0…
PriorityP340medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.50%
39.1th percentile
A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | >= 7.4.1 < 7.4.9 | 7.4.9 |
| fortinet | fortiweb | 7.4.1 – 7.4.8 | — |
| fortinet | fortiweb | >= 7.6.0 < 7.6.4 | 7.6.4 |
| fortinet | fortiweb | 7.6.0 – 7.6.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in F...
vendor_fortinet·2025-08-12·CVSS 6.7
CVE-2025-47857 [MEDIUM] CWE-78 A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in F...
FG-IR-25-253: A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in F...
A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands.
CVEs: CVE-2025-47857
CWEs: CWE-78
CVSS: 6.7 (medium)
Affected products: FortiWeb, Fortinet
GHSA
GHSA-9wp6-c53h-c89m: A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7
ghsa_unreviewed·2025-08-12
CVE-2025-47857 [MEDIUM] CWE-78 GHSA-9wp6-c53h-c89m: A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7
A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-12
Published