CVE-2025-53609: Path Traversal
A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53609?
CVE-2025-53609 is considered a high severity vulnerability due to its potential for arbitrary file read exploits.
How do I fix CVE-2025-53609?
To fix CVE-2025-53609, update FortiWeb to the latest version that addresses this vulnerability.
What versions of FortiWeb are affected by CVE-2025-53609?
CVE-2025-53609 affects FortiWeb versions 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, and 7.0.2 through 7.0.11.
What type of vulnerability is CVE-2025-53609?
CVE-2025-53609 is a Relative Path Traversal vulnerability categorized under CWE-23.
Can CVE-2025-53609 be exploited remotely?
CVE-2025-53609 requires authentication, so an attacker must have valid credentials to exploit the vulnerability.