CVE-2025-66178 — OS Command Injection in Fortinet Fortiweb
Severity
7.2HIGHNVD
EPSS
0.0%
top 85.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 10
Description
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow an authenticated attacked to execute arbitrary commands via a specialy crafted HTTP request.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-hh5r-8mxw-p8h8: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8↗2026-03-10
CVEList▶
CVE-2025-66178: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8↗2026-03-10