FortiWeb management GUI
CVE-2025-64446: FortiWeb authentication bypass that creates admin accounts
A path traversal plus a trusted request header lets an unauthenticated attacker act as any FortiWeb user, including admin. Exploited since at least early October 2025, with a public proof of concept, and fixed from 8.0.2.
Published Updated
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| FortiWeb 8.0.0 to 8.0.1 | 8.0.2 or later |
| FortiWeb 7.6.0 to 7.6.4 | 7.6.5 or later |
| FortiWeb 7.4.0 to 7.4.9 | 7.4.10 or later |
| FortiWeb 7.2.0 to 7.2.11 | 7.2.12 or later |
| FortiWeb 7.0.0 to 7.0.11 | 7.0.12 or later |
| FortiWeb 6.4 and 6.3 (unsupported) | No fix. Fortinet lists 6.4 as not affected, but Rapid7 and watchTowr say it is. Migrate to a fixed release |
| FortiAppSec Cloud | Not affected |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
FortiWeb is Fortinet’s web application firewall. Its management interface has two bugs that work together, per watchTowr:
- Path traversal. A request that starts with a valid API path can be walked back to
cgi-bin/fwbcgi, an internal CGI program. - No real authentication.
fwbcgireads aCGIINFOheader, Base64-decodes it and trusts the user name and profile inside. An attacker can claim to be the built-inadmin.
The result: an unauthenticated attacker with network access to the management interface becomes administrator. In the attacks watchTowr saw, they created new local admin accounts as persistence. watchTowr calls this a complete compromise of the appliance.
It matters because it was exploited before the advisory. Arctic Wolf dates attempts to early October 2025, and Defused published a proof of concept on October 6. Fortinet’s advisory came on November 14. Researchers also described it as silently patched: Rapid7 found the public exploit fails on 8.0.2 although the release notes don’t mention a fix. A public exploit and a Metasploit module exist. Related: CVE-2025-58034, an authenticated command injection in FortiWeb that Fortinet also reports as exploited.
Scores differ: Fortinet’s advisory says CVSS 9.4. Rapid7 quotes 9.1 and some databases list 9.8. CISA lists known ransomware use as unknown.
Am I affected?
You are affected if you run FortiWeb older than 8.0.2, 7.6.5, 7.4.10, 7.2.12 or 7.0.12, and an attacker can reach the HTTP or HTTPS management interface. Fortinet says that exposure on an internal-only management interface greatly reduces the risk. It does not remove it for an attacker already inside your network.
FortiWeb 6.x: Fortinet lists 6.4 as not affected. Rapid7 confirmed unsupported 6.x versions are vulnerable, and watchTowr lists 6.4.3 and earlier and 6.3.23 and earlier. Independent testing contradicts the vendor here, so treat 6.x as vulnerable and plan to move off it.
FortiAppSec Cloud is not affected.
To test an appliance, watchTowr’s version check sends a GET to the traversal path and expects HTTP 200 when vulnerable and 403 when patched. Their Detection Artefact Generator on GitHub goes further and creates a test user on the target. Only run it on devices you own, and delete the account afterwards.
What to do
- Upgrade to 8.0.2, 7.6.5, 7.4.10, 7.2.12, 7.0.12 or later. Back up the configuration first.
- If you can’t upgrade tonight, Fortinet’s workaround is to disable HTTP and HTTPS on internet-facing interfaces. You lose remote GUI and API management on those interfaces, so make sure you have another way to administer the device (for example from an internal network).
- Take management interfaces off the internet and restrict them to a management network or VPN, even after patching.
- Assume compromise if an unpatched device was reachable at any time since early October 2025. Fortinet tells customers to review the configuration and logs for unexpected changes or unauthorized administrator accounts. Specifically:
- List all administrator accounts and remove any you can’t explain.
- Compare the configuration against a known-good backup.
- If you find unknown admins, rebuild the appliance and rotate every credential and certificate private key stored on it. Upgrading alone does not undo changes an attacker made.
- Check what the FortiWeb connects to. Arctic Wolf expects continued targeting because FortiWeb integrates with other Fortinet products.
Detection
- New or unknown administrator accounts, especially local ones with the
prof_adminprofile. Attackers usedTestpoint,trader1andtrader(see the indicators below). Rapid7’s test exploit createdhax0r. Any name is possible, so review the whole list. - Requests to the traversal path. Arctic Wolf saw
POST /api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi. watchTowr’s sample uses a similar path with aCGIINFOheader and a JSON body that defines a new user. Search web, proxy and packet logs forfwbcgiand forCGIINFO. - Unexpected configuration changes around those requests.
- Scanner signatures: Rapid7 has an unauthenticated vulnerability check (SAFE mode must be off) and a Sigma rule in its Intelligence Hub.
- Requests from the addresses below. Check your logs back to early October 2025.
Indicators of compromise
Passwords seen on the attackers' admin accounts: 3eMIXX43, AFT3$tH4ck and AFT3$tH4ckmet0d4yaga!n. A public exploit is available, so expect other names and addresses too: check for any admin account you can't explain.
The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2025-64446.txt
| Indicator | Type | Reported by |
|---|---|---|
| 64.95.13[.]8 | IPFrom the first report of exploitation, October 2025 | Defused |
| 107.152.41[.]19 | IP | Defused and PwnDefend, via BleepingComputer |
| 144.31.1[.]63 | IP | Defused and PwnDefend, via BleepingComputer |
| 185.192.70[.]0/24 | IPAddress range | Defused and PwnDefend, via BleepingComputer |
| Testpoint | Account nameAdmin account created by attackers | Defused and PwnDefend, via BleepingComputer |
| trader1 | Account nameAdmin account created by attackers | Defused and PwnDefend, via BleepingComputer |
| trader | Account nameAdmin account created by attackers | Defused and PwnDefend, via BleepingComputer |
Sources
Page changelog
- Full analysis published.
- Added indicators of compromise from Defused and PwnDefend.
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.