CVE-2025-25254: Directory Traversal
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb endpoint may allow an authenticated admin to access and modify the filesystem via crafted requests.
Other sources
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all versions, 7.0 all versions endpoint may allow an authenticated admin to access and modify the filesystem via crafted requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25254?
The severity of CVE-2025-25254 is classified as high due to its potential for unauthorized access and modification of the filesystem by an authenticated user.
How do I fix CVE-2025-25254?
To fix CVE-2025-25254, upgrade FortiWeb to version 7.6.3 or later, 7.4.7 or later, or apply the necessary patches as provided by Fortinet.
Who is affected by CVE-2025-25254?
CVE-2025-25254 affects FortiWeb versions 7.6.2 and below, 7.4.6 and below, and all versions of 7.2 and 7.0.
What types of vulnerabilities does CVE-2025-25254 represent?
CVE-2025-25254 represents an Improper Limitation of a Pathname to a Restricted Directory vulnerability, commonly known as Path Traversal.
Can CVE-2025-25254 be exploited remotely?
CVE-2025-25254 requires authentication, meaning that only authenticated admins can exploit this vulnerability.