Fortinet Product Security Update Advisory (CVE-2025-25257)

Fortinet Product Security Update Advisory (CVE-2025-25257)

Overview

 

We have released security updates to fix vulnerabilities in Fortinet products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-25257

 

FortiWeb 7.6 Versions: 7.6.0 and later and 7.6.3 and earlier
FortiWeb 7.4 Versions: 7.4.0 and later and 7.4.7 and earlier
FortiWeb 7.2 versions: 7.2.0 or later and 7.2.10 or earlier
FortiWeb 7.0 versions: 7.0.0 or later and 7.0.10 or earlier

 

 

Resolved Vulnerabilities

 

Unauthorized SQL code execution vulnerability due to lack of input validation in FortiWeb

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2025-25257

 

FortiWeb 7.6 versions: 7.6.4 and later
FortiWeb 7.4 versions: 7.4.8 and later
FortiWeb 7.2 Version: 7.2.11 and later
FortiWeb 7.0 Version: 7.0.11 and later

 

 

References

 

[1] Unauthenticated SQL injection in GUI
https://fortiguard.fortinet.com/psirt/FG-IR-25-151