{"id":8481,"date":"2025-11-15T10:03:44","date_gmt":"2025-11-15T10:03:44","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/15\/critical-fortiweb-waf-flaw-exploited-in-the-wild-enabling-full-admin-takeover\/"},"modified":"2025-11-15T10:03:44","modified_gmt":"2025-11-15T10:03:44","slug":"critical-fortiweb-waf-flaw-exploited-in-the-wild-enabling-full-admin-takeover","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/15\/critical-fortiweb-waf-flaw-exploited-in-the-wild-enabling-full-admin-takeover\/","title":{"rendered":"Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover"},"content":{"rendered":"<p>    Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Fortinet has issued an urgent advisory warning of a critical vulnerability in its FortiWeb <a href=\"https:\/\/cybersecuritynews.com\/best-web-application-firewall-waf\/\" target=\"_blank\" rel=\"noreferrer noopener\">web application firewall<\/a> (WAF) product, which attackers are actively exploiting in the wild.<\/p>\n<p>Identified as CVE-2025-64446, the flaw stems from <a href=\"https:\/\/cybersecuritynews.com\/windows-improper-access-control-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">improper access control<\/a> in the GUI component, allowing unauthenticated threat actors to execute administrative commands and potentially seize complete control of affected systems.<\/p>\n<p>The vulnerability, classified as a relative path traversal issue (CWE-23), enables attackers to craft malicious HTTP or HTTPS requests that bypass authentication.<\/p>\n<p>This could lead to the creation of unauthorized administrator accounts, granting full access to the device\u2019s configuration and sensitive data. Fortinet\u2019s Product Security Incident Response Team (PSIRT) confirmed active exploitation and urged immediate patching to mitigate risks.<\/p>\n<p>With a CVSS v3.1 base score of 9.1 (AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H), the flaw earns a \u201cCritical\u201d severity rating per National Vulnerability Database (NVD) standards. It affects multiple FortiWeb versions across branches 8.0, 7.6, 7.4, 7.2, and 7.0. Specifically:<\/p>\n<ul class=\"wp-block-list\">\n<li>FortiWeb 8.0.0 through 8.0.1<\/li>\n<li>FortiWeb 7.6.0 through 7.6.4<\/li>\n<li>FortiWeb 7.4.0 through 7.4.9<\/li>\n<li>FortiWeb 7.2.0 through 7.2.11<\/li>\n<li>FortiWeb 7.0.0 through 7.0.11<\/li>\n<\/ul>\n<p>Users should upgrade to the latest patched versions: 8.0.2 or above, 7.6.5 or above, 7.4.10 or above, 7.2.12 or above, or 7.0.12 or above, respectively. Detailed CVRF and CSAF files are available on FortiGuard for automated integration.<\/p>\n<p>As a temporary workaround, Fortinet recommends disabling HTTP or HTTPS access on internet-facing interfaces, aligning with best practices that limit management access to internal networks only. This reduces exposure significantly but doesn\u2019t eliminate the threat entirely.<\/p>\n<p>Post-upgrade, organizations must audit configurations and logs for signs of compromise, such as unexpected admin account additions or modifications. Fortinet emphasized reviewing access patterns to detect any lingering unauthorized activity.<\/p>\n<p>This incident highlights the persistent risks to network security appliances, which are prime targets for attackers seeking to pivot into broader environments.<\/p>\n<p>As WAFs like FortiWeb protect web applications from threats, they can also introduce ironic backdoors through their own vulnerabilities. Security experts advise prioritizing patches for critical infrastructure, especially given the flaw\u2019s ease of exploitation, as no privileges or user interaction are required.<\/p>\n<p>Fortinet\u2019s <a href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-25-910\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">advisory<\/a>, published today, underscores the company\u2019s commitment to rapid disclosure. For more details, visit the FortiGuard PSIRT page. As exploitation continues, unpatched systems remain highly vulnerable.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/fortiweb-waf-flaw-exploited-in-the-wild\/\">Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/fortiweb-waf-flaw-exploited-in-the-wild\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover Fortinet has issued an urgent advisory warning of a critical vulnerability in its FortiWeb web application firewall (WAF) product, which attackers are actively exploiting in the wild. Identified as CVE-2025-64446, the flaw stems from improper access control in the GUI component, allowing unauthenticated [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-8481","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8481"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8481"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8481\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8481"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8481"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}