FortiWeb management GUI

CVE-2025-64446: FortiWeb authentication bypass that creates admin accounts

A path traversal plus a trusted request header lets an unauthenticated attacker act as any FortiWeb user, including admin. Exploited since at least early October 2025, with a public proof of concept, and fixed from 8.0.2.

Published Updated

ExploitedYes, in CISA KEVAdded 14 Nov 2025
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 3.1 9.4
EPSS92%Chance of exploitation in 30 days
Public exploitYes
FixAvailable

Affected and fixed versions

Product / branchFixed in
FortiWeb 8.0.0 to 8.0.18.0.2 or later
FortiWeb 7.6.0 to 7.6.47.6.5 or later
FortiWeb 7.4.0 to 7.4.97.4.10 or later
FortiWeb 7.2.0 to 7.2.117.2.12 or later
FortiWeb 7.0.0 to 7.0.117.0.12 or later
FortiWeb 6.4 and 6.3 (unsupported)No fix. Fortinet lists 6.4 as not affected, but Rapid7 and watchTowr say it is. Migrate to a fixed release
FortiAppSec CloudNot affected

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

FortiWeb is Fortinet’s web application firewall. Its management interface has two bugs that work together, per watchTowr:

  1. Path traversal. A request that starts with a valid API path can be walked back to cgi-bin/fwbcgi, an internal CGI program.
  2. No real authentication. fwbcgi reads a CGIINFO header, Base64-decodes it and trusts the user name and profile inside. An attacker can claim to be the built-in admin.

The result: an unauthenticated attacker with network access to the management interface becomes administrator. In the attacks watchTowr saw, they created new local admin accounts as persistence. watchTowr calls this a complete compromise of the appliance.

It matters because it was exploited before the advisory. Arctic Wolf dates attempts to early October 2025, and Defused published a proof of concept on October 6. Fortinet’s advisory came on November 14. Researchers also described it as silently patched: Rapid7 found the public exploit fails on 8.0.2 although the release notes don’t mention a fix. A public exploit and a Metasploit module exist. Related: CVE-2025-58034, an authenticated command injection in FortiWeb that Fortinet also reports as exploited.

Scores differ: Fortinet’s advisory says CVSS 9.4. Rapid7 quotes 9.1 and some databases list 9.8. CISA lists known ransomware use as unknown.

Am I affected?

You are affected if you run FortiWeb older than 8.0.2, 7.6.5, 7.4.10, 7.2.12 or 7.0.12, and an attacker can reach the HTTP or HTTPS management interface. Fortinet says that exposure on an internal-only management interface greatly reduces the risk. It does not remove it for an attacker already inside your network.

FortiWeb 6.x: Fortinet lists 6.4 as not affected. Rapid7 confirmed unsupported 6.x versions are vulnerable, and watchTowr lists 6.4.3 and earlier and 6.3.23 and earlier. Independent testing contradicts the vendor here, so treat 6.x as vulnerable and plan to move off it.

FortiAppSec Cloud is not affected.

To test an appliance, watchTowr’s version check sends a GET to the traversal path and expects HTTP 200 when vulnerable and 403 when patched. Their Detection Artefact Generator on GitHub goes further and creates a test user on the target. Only run it on devices you own, and delete the account afterwards.

What to do

  1. Upgrade to 8.0.2, 7.6.5, 7.4.10, 7.2.12, 7.0.12 or later. Back up the configuration first.
  2. If you can’t upgrade tonight, Fortinet’s workaround is to disable HTTP and HTTPS on internet-facing interfaces. You lose remote GUI and API management on those interfaces, so make sure you have another way to administer the device (for example from an internal network).
  3. Take management interfaces off the internet and restrict them to a management network or VPN, even after patching.
  4. Assume compromise if an unpatched device was reachable at any time since early October 2025. Fortinet tells customers to review the configuration and logs for unexpected changes or unauthorized administrator accounts. Specifically:
    • List all administrator accounts and remove any you can’t explain.
    • Compare the configuration against a known-good backup.
    • If you find unknown admins, rebuild the appliance and rotate every credential and certificate private key stored on it. Upgrading alone does not undo changes an attacker made.
  5. Check what the FortiWeb connects to. Arctic Wolf expects continued targeting because FortiWeb integrates with other Fortinet products.

Detection

  • New or unknown administrator accounts, especially local ones with the prof_admin profile. Attackers used Testpoint, trader1 and trader (see the indicators below). Rapid7’s test exploit created hax0r. Any name is possible, so review the whole list.
  • Requests to the traversal path. Arctic Wolf saw POST /api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi. watchTowr’s sample uses a similar path with a CGIINFO header and a JSON body that defines a new user. Search web, proxy and packet logs for fwbcgi and for CGIINFO.
  • Unexpected configuration changes around those requests.
  • Scanner signatures: Rapid7 has an unauthenticated vulnerability check (SAFE mode must be off) and a Sigma rule in its Intelligence Hub.
  • Requests from the addresses below. Check your logs back to early October 2025.

Indicators of compromise

Passwords seen on the attackers' admin accounts: 3eMIXX43, AFT3$tH4ck and AFT3$tH4ckmet0d4yaga!n. A public exploit is available, so expect other names and addresses too: check for any admin account you can't explain.

The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2025-64446.txt

IndicatorTypeReported by
64.95.13[.]8IPFrom the first report of exploitation, October 2025Defused
107.152.41[.]19IPDefused and PwnDefend, via BleepingComputer
144.31.1[.]63IPDefused and PwnDefend, via BleepingComputer
185.192.70[.]0/24IPAddress rangeDefused and PwnDefend, via BleepingComputer
TestpointAccount nameAdmin account created by attackersDefused and PwnDefend, via BleepingComputer
trader1Account nameAdmin account created by attackersDefused and PwnDefend, via BleepingComputer
traderAccount nameAdmin account created by attackersDefused and PwnDefend, via BleepingComputer

Sources

Page changelog

  • Full analysis published.
  • Added indicators of compromise from Defused and PwnDefend.

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.