A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands.
2025-08-12T19:15:29.997
2025-08-15T12:25:37.050
Analyzed
CVSSv3.1: 6.7 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | fortinet | fortiweb | < 7.4.9 | Yes |
| Application | fortinet | fortiweb | < 7.6.4 | Yes |