CVE-2025-59669
A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker with shell
Severity
Medium 4.8
CVSS 3.1
Exploited
Not listed
EPSS
0.001
2.0th percentile
Discovered by
Third party
Vendor advisory field
Published
Nov 18, 2025
Assigned by fortinet
Description
A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker with shell access to the device to connect to redis service and access its data
Weakness: CWE-798
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiWeb | Web & Application Security | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiWeb
Credit
Fortinet is pleased to thank Victor Pasman for reporting this vulnerability under responsible disclosure.
Vendor remediation
Upgrade to FortiWeb version 7.6.1 or above