Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-64471


A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to use the hash in place of the password to authenticate via crafted HTTP/HTTPS requests


Published

2025-12-09T18:16:05.403

Last Modified

2025-12-10T19:16:14.843

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-836

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet fortiweb ≤ 7.0.11 Yes
Application fortinet fortiweb ≤ 7.2.11 Yes
Application fortinet fortiweb ≤ 7.4.10 Yes
Application fortinet fortiweb ≤ 7.6.4 Yes
Application fortinet fortiweb ≤ 8.0.1 Yes

References