OS Command Injection Vulnerability in Fortinet FortiWeb
CVE-2025-27759
6.7MEDIUM
What is CVE-2025-27759?
An OS command injection vulnerability exists in Fortinet FortiWeb products, allowing an authenticated privileged attacker to execute unauthorized commands. The flaw arises from improper handling of special elements in command inputs across several versions, particularly affecting FortiWeb versions ranging from 7.6.0 to 7.6.3, 7.4.0 to 7.4.7, and 7.2.0 to 7.2.10. This vulnerability can lead to severe security breaches if exploited, making it imperative for users to apply available patches and secure their systems.
Affected Version(s)
FortiWeb 7.6.0 <= 7.6.3
FortiWeb 7.4.0 <= 7.4.7
FortiWeb 7.2.0 <= 7.2.10