CVE-2025-52970
high · 8.1A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.
8.1
CVSS
10.1%
EPSS (exploit prob.)
95th
EPSS percentile
2025-08-12
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-233
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fortinet | fortiweb | >= 7.0.0, < 7.0.11 |
| fortinet | fortiweb | >= 7.2.0, < 7.2.11 |
| fortinet | fortiweb | >= 7.4.0, < 7.4.8 |
| fortinet | fortiweb | >= 7.6.0, < 7.6.4 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-52970