First published: Tue Apr 08 2025(Updated: )
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb endpoint may allow an authenticated admin to access and modify the filesystem via crafted requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiWeb | <7.6.2<7.4.6>=7.2>=7.0 | |
Fortinet FortiWeb | >=7.6.0<=7.6.2 | |
Fortinet FortiWeb | >=7.4.0<=7.4.6 | |
Fortinet FortiWeb | >=7.2 | |
Fortinet FortiWeb | >=7.0 |
Please upgrade to FortiWeb version 7.6.3 or above Please upgrade to FortiWeb version 7.4.7 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-25254 is classified as high due to its potential for unauthorized access and modification of the filesystem by an authenticated user.
To fix CVE-2025-25254, upgrade FortiWeb to version 7.6.3 or later, 7.4.7 or later, or apply the necessary patches as provided by Fortinet.
CVE-2025-25254 affects FortiWeb versions 7.6.2 and below, 7.4.6 and below, and all versions of 7.2 and 7.0.
CVE-2025-25254 represents an Improper Limitation of a Pathname to a Restricted Directory vulnerability, commonly known as Path Traversal.
CVE-2025-25254 requires authentication, meaning that only authenticated admins can exploit this vulnerability.