Fortinet FortiWeb has been exploited! Patch Now!
The US Cybersecurity and Infrastructure Securityn Agency (CISA) has provided an alert on exploitation of Fortinet FortiWeb through a SQL injection vulnerability that is tracked as CVE-2025-25257. The critical vulnerability exists in the following versions of the security product: 7.6.0 through 7.6.3, 7.4.0 through 7.4.7 and 7.2.0 through 7.2.10 and those below 7.0.10. The upgrades for each of the ranges has been provided by Fortinet. For working around the SQL injection vulnerability, the HTTP/HTTPS administrative interface msut be disabled.
Comments
Post a Comment