CVE-2025-27759: OS Command Injection
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and before 7.0.10 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI commands
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27759?
CVE-2025-27759 has a high severity rating due to the potential for an authenticated attacker to execute unauthorized code.
How can I mitigate CVE-2025-27759?
To mitigate CVE-2025-27759, update Fortinet FortiWeb to version 7.6.4 or later as soon as possible.
Who is affected by CVE-2025-27759?
CVE-2025-27759 affects users of Fortinet FortiWeb versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, and versions prior to 7.0.10.
What type of vulnerability is CVE-2025-27759?
CVE-2025-27759 is classified as an OS Command Injection vulnerability under CWE-78.
Can CVE-2025-27759 be exploited remotely?
CVE-2025-27759 requires local authentication, meaning it cannot be remotely exploited without valid credentials.