imPC@ndo IT

Tracker / CVE-2025-64447

CVE-2025-64447

High 8.1

A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS request via forged cookies, requiring prior knowledge of the FortiWeb serial number.

Affected products and versions

fortinet fortiweb · 7.0.0 → 7.0.11
fortinet fortiweb · 7.2.0 → 7.2.11
fortinet fortiweb · 7.4.0 → 7.4.10
fortinet fortiweb · 7.6.0 → 7.6.5
fortinet fortiweb · 8.0.0 → 8.0.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References