Cookie Validation and Integrity Vulnerability in Fortinet FortiWeb Products
CVE-2025-64447
7.1HIGH
What is CVE-2025-64447?
The vulnerability stems from Fortinet FortiWeb's reliance on cookies without adequate validation and integrity checking. This flaw potentially enables unauthenticated attackers to execute arbitrary operations on the affected systems by sending specially crafted HTTP or HTTPS requests containing forged cookies. Exploiting this vulnerability may require prior knowledge of the FortiWeb serial number, heightening the risk of unauthorized access and system manipulation.
Affected Version(s)
FortiWeb 8.0.0 <= 8.0.1
FortiWeb 7.6.0 <= 7.6.5
FortiWeb 7.4.0 <= 7.4.10