CVE-2025-52970
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-12

Last updated on: 2025-08-15

Assigner: Fortinet, Inc.

Description
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-12
Last Modified
2025-08-15
Generated
2026-05-27
AI Q&A
2025-08-12
EPSS Evaluated
2026-05-25
NVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
fortinet fortiweb From 7.0.0 (inc) to 7.0.11 (exc)
fortinet fortiweb From 7.2.0 (inc) to 7.2.11 (exc)
fortinet fortiweb From 7.4.0 (inc) to 7.4.8 (exc)
fortinet fortiweb From 7.6.0 (inc) to 7.6.4 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-233 The product does not properly handle when the expected number of parameters, fields, or arguments is not provided in input, or if those parameters are undefined.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is due to improper handling of parameters in certain versions of Fortinet FortiWeb. It allows an unauthenticated remote attacker, who has some non-public information about the device and targeted user, to send a specially crafted request that can grant them administrative privileges on the device.


How can this vulnerability impact me? :

If exploited, this vulnerability can allow an attacker to gain admin privileges on the affected Fortinet FortiWeb device without authentication. This could lead to full control over the device, potentially compromising the security and availability of the protected network and applications.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart