CISA has ordered U.S. government agencies to secure their systems within a week against another vulnerability in Fortinet's FortiWeb web application firewall, which was exploited in zero-day attacks. Tracked as CVE-2025-58034, this OS command injection flaw can allow authenticated threat actors to execute code as root in low-complexity attacks that don't require user interaction. "An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands," Fortinet said on Tuesday. "The specific flaw exists within the implementation of the policy_scripting_post_handler method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root," noted the Trend Micro research team who reported the vulnerability. CISA added CVE-2025-58034 to its Known Exploited Vulnerabilities Catalog the same day, giving Federal Civilian Executive Branch (FCEB) agencies until Tuesday, November 25th, to secure their systems against attacks as mandated by the Binding Operational Directive (BOD) 22-01. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," CISA warned. "With recent and ongoing ex...
CISA gives govt agencies 7 days to patch new Fortinet flaw
Affected Software
Frequently Asked Questions
Which organizations have been directed to address CVE-2025-58034?
CISA ordered U.S. Federal Civilian Executive Branch agencies to secure affected systems within a week. The vulnerability affects Fortinet FortiWeb web application firewalls.
What does successful exploitation of this flaw allow?
An authenticated attacker can execute unauthorized code on the underlying FortiWeb system as root. Exploitation is described as low complexity and does not require user interaction.
How can an attacker trigger CVE-2025-58034?
Fortinet said the OS command injection issue can be exploited through crafted HTTP requests or CLI commands. The flaw is in the policy_scripting_post_handler method, which does not properly validate a user-supplied string before it is used in a system call.
Is exploitation of the FortiWeb vulnerability confirmed?
Yes. The flaw was exploited in zero-day attacks, and CISA added CVE-2025-58034 to its Known Exploited Vulnerabilities Catalog on the same day.