Cookie Validation and Integrity Vulnerability in Fortinet FortiWeb Products
CVE-2025-64447

7.1HIGH

Key Information:

Vendor

Fortinet

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-64447?

The vulnerability stems from Fortinet FortiWeb's reliance on cookies without adequate validation and integrity checking. This flaw potentially enables unauthenticated attackers to execute arbitrary operations on the affected systems by sending specially crafted HTTP or HTTPS requests containing forged cookies. Exploiting this vulnerability may require prior knowledge of the FortiWeb serial number, heightening the risk of unauthorized access and system manipulation.

Affected Version(s)

FortiWeb 8.0.0 <= 8.0.1

FortiWeb 7.6.0 <= 7.6.5

FortiWeb 7.4.0 <= 7.4.10

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.