CVE-2025-66178

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 throug

Severity
Medium 6.7
CVSS 3.1
Exploited
Not listed
EPSS
0.017
75.8th percentile
Discovered by
Vendor
Vendor advisory field
Published
Mar 10, 2026
Assigned by fortinet

Description

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow an authenticated attacked to execute arbitrary commands via a specialy crafted HTTP request.

Weakness: CWE-78

Affected products

Vendor Product Category Matched by
Fortinet FortiWeb Web & Application Security cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiWeb

Credit

Internally discovered and reported by Loic Pantano of Fortinet PSIRT

Vendor remediation

Upgrade to FortiWeb version 8.0.3 or above Upgrade to FortiWeb version 7.6.7 or above Upgrade to FortiWeb version 7.4.12 or above Upgrade to upcoming FortiWeb version 7.2.13 or above Upgrade to upcoming FortiWeb version 7.0.13 or above

Something wrong here?