CVE-2025-25257: Fortinet FortiWeb SQL Injection Vulnerability. Fortinet
Fortinet FortiWeb SQL Injection Vulnerability. Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
- CISA KEV-listed (remediation due 2025-08-08)
- EPSS 26.2% (96.4% percentile)