CVE-2025-27759

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and before 7.0.10 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI commands
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

14 Aug 2025, 01:21

Type Values Removed Values Added
References () https://fortiguard.fortinet.com/psirt/FG-IR-25-150 - () https://fortiguard.fortinet.com/psirt/FG-IR-25-150 - Vendor Advisory
First Time Fortinet fortiweb
Fortinet
CPE cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

13 Aug 2025, 17:33

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando del SO ('OS Command Injection') [CWE-78] en Fortinet FortiWeb versión 7.6.0 a 7.6.3, 7.4.0 a 7.4.7, 7.2.0 a 7.2.10 y anteriores a 7.0.10 permite que un atacante privilegiado autenticado ejecute código o comandos no autorizados a través de comandos CLI manipulados.

12 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-12 19:15

Updated : 2025-08-14 01:21


NVD link : CVE-2025-27759

Mitre link : CVE-2025-27759

CVE.ORG link : CVE-2025-27759


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')