CVE-2025-64471: High severity Fortinet FortiWeb vulnerability
A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to use the hash in place of the password to authenticate via crafted HTTP/HTTPS requests
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64471?
The severity of CVE-2025-64471 is classified as high, due to the potential for unauthenticated access to sensitive information.
How do I fix CVE-2025-64471?
To fix CVE-2025-64471, upgrade Fortinet FortiWeb to version 8.0.2 or later, or to the latest version of the affected series.
Which versions of Fortinet FortiWeb are affected by CVE-2025-64471?
CVE-2025-64471 affects FortiWeb versions 8.0.0 to 8.0.1, 7.6.0 to 7.6.4, 7.4.0 to 7.4.10, 7.2.0 to 7.2.11, and 7.0.0 to 7.0.11.
What type of vulnerability is CVE-2025-64471?
CVE-2025-64471 is a use of password hash instead of password for authentication vulnerability.
Could CVE-2025-64471 allow unauthorized access?
Yes, CVE-2025-64471 may allow an unauthenticated attacker to bypass security measures and gain access.