CVE-2025-66178OS Command Injection in Fortinet Fortiweb

Severity
7.2HIGHNVD
EPSS
0.0%
top 85.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 10

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow an authenticated attacked to execute arbitrary commands via a specialy crafted HTTP request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortiweb7.0.07.0.13+4
CVEListV5fortinet/fortiweb8.0.08.0.1+4

🔴Vulnerability Details

2
GHSA
GHSA-hh5r-8mxw-p8h8: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 82026-03-10
CVEList
CVE-2025-66178: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 82026-03-10

📋Vendor Advisories

1
Fortinet
OS Command injection in FortiWeb API2026-03-10

🕵️Threat Intelligence

1
Wiz
CVE-2025-66178 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-66178 — OS Command Injection in Fortinet | cvebase