HomeCyber SecurityFortinet Releases Patch for Essential SQL Injection Flaw in FortiWeb (CVE-2025-25257)

Fortinet Releases Patch for Essential SQL Injection Flaw in FortiWeb (CVE-2025-25257)


Jul 11, 2025Ravie LakshmananUnited States

Fortinet Releases Patch for Essential SQL Injection Flaw in FortiWeb (CVE-2025-25257)

Fortinet has launched fixes for a vital safety flaw impacting FortiWeb that would allow an unauthenticated attacker to run arbitrary database instructions on vulnerable cases.

Tracked as CVE-2025-25257, the vulnerability carries a CVSS rating of 9.6 out of a most of 10.0.

“An improper neutralization of particular components utilized in an SQL command (‘SQL Injection’) vulnerability [CWE-89] in FortiWeb could enable an unauthenticated attacker to execute unauthorized SQL code or instructions through crafted HTTP or HTTPs requests,” Fortinet stated in an advisory launched this week.

Cybersecurity

The shortcoming impacts the next variations –

  • FortiWeb 7.6.0 by means of 7.6.3 (Improve to 7.6.4 or above)
  • FortiWeb 7.4.0 by means of 7.4.7 (Improve to 7.4.8 or above)
  • FortiWeb 7.2.0 by means of 7.2.10 (Improve to 7.2.11 or above)
  • FortiWeb 7.0.0 by means of 7.0.10 (Improve to 7.0.11 or above)

Kentaro Kawane from GMO Cybersecurity, who was just lately credited with reporting a set of vital flaws in Cisco Id Companies and ISE Passive Id Connector (CVE-2025-20286, CVE-2025-20281, and CVE-2025-20282), has been acknowledged for locating the problem.

In an evaluation revealed right this moment, watchTowr Labs stated the issue is rooted in a operate referred to as “get_fabric_user_by_token” that is related to the Cloth Connector element, which acts as a bridge between FortiWeb and different Fortinet merchandise.

The operate, in flip, is invoked from one other operate named “fabric_access_check,” that is referred to as from three totally different API endpoints: “/api/material/gadget/standing,” “/api/v[0-9]/material/widget/[a-z]+,” and “/api/v[0-9]/material/widget.”

The problem is that attacker-controlled enter – handed through a Bearer token Authorization header in a specifically crafted HTTP request – is handed on to an SQL database question with out satisfactory sanitization to be sure that it isn’t dangerous and doesn’t embrace any malicious code.

The assault will be prolonged additional by embedding a SELECT … INTO OUTFILE assertion to write down the outcomes of command execution to a file within the underlying working system by profiting from the truth that the question is run because the “mysql” person.

Cybersecurity

“The brand new model of the operate replaces the earlier format-string question with ready statements – an inexpensive try to forestall simple SQL injection,” safety researcher Sina Kheirkhah stated.

As short-term workarounds till the required patches will be utilized, customers are really helpful to disable HTTP/HTTPS administrative interface.

With flaws in Fortinet gadgets having been exploited by menace actors prior to now, it is important that customers transfer shortly to replace to the most recent model to mitigate potential dangers.

Discovered this text attention-grabbing? Observe us on Twitter and LinkedIn to learn extra unique content material we submit.



RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments