Fortinet Product Security Update Advisory (CVE-2025-25257)
Overview
We have released security updates to fix vulnerabilities in Fortinet products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-25257
FortiWeb 7.6 Versions: 7.6.0 and later and 7.6.3 and earlier
FortiWeb 7.4 Versions: 7.4.0 and later and 7.4.7 and earlier
FortiWeb 7.2 versions: 7.2.0 or later and 7.2.10 or earlier
FortiWeb 7.0 versions: 7.0.0 or later and 7.0.10 or earlier
Resolved Vulnerabilities
Unauthorized SQL code execution vulnerability due to lack of input validation in FortiWeb
Vulnerability Patches
Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-25257
FortiWeb 7.6 versions: 7.6.4 and later
FortiWeb 7.4 versions: 7.4.8 and later
FortiWeb 7.2 Version: 7.2.11 and later
FortiWeb 7.0 Version: 7.0.11 and later
References
[1] Unauthenticated SQL injection in GUI
https://fortiguard.fortinet.com/psirt/FG-IR-25-151