Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-47857


A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands.


Published

2025-08-12T19:15:29.997

Last Modified

2025-08-15T12:25:37.050

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiweb < 7.4.9 Yes
Application fortinet fortiweb < 7.6.4 Yes

References