CVE-2025-66178: OS Command Injection
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow an authenticated attacked to execute arbitrary commands via a specialy crafted HTTP request.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66178?
CVE-2025-66178 has been assigned a high severity rating due to its potential impact on system security through os command injection.
How do I fix CVE-2025-66178?
To mitigate CVE-2025-66178, ensure that you update Fortinet FortiWeb to the latest version that has addressed this vulnerability.
Which versions of Fortinet FortiWeb are affected by CVE-2025-66178?
CVE-2025-66178 affects Fortinet FortiWeb versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.5, 7.4.0 through 7.4.11, 7.2.0 through 7.2.12, and 7.0.0 through 7.0.12.
What type of vulnerability is CVE-2025-66178?
CVE-2025-66178 is categorized as an os command injection vulnerability that arises from improper neutralization of special elements.
Can CVE-2025-66178 be exploited by unauthenticated users?
CVE-2025-66178 requires authentication, meaning it can only be exploited by authenticated users with access to the affected Fortinet FortiWeb systems.