CVE-2025-52970
CVE-2025-52970
8.1
HighPublished:
Last updated:
Source:psirt@fortinet.com
Analyzed
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.
References
psirt@fortinet.com
https://fortiguard.fortinet.com/psirt/FG-IR-25-448134c704f-9b21-4f2e-91b3-4a467353bcc0
https://pwner.gg/blog/2025-08-13-fortiweb-cve-2025-52970