Fortinet has released an emergency patch addressing a critical SQL Injection vulnerability (CVE‑2025‑25257) in its FortiWeb web application firewall. With a high severity score of 9.6/10 under the Common Vulnerability Scoring System (CVSS), the flaw could allow unauthenticated attackers to inject and execute arbitrary SQL commands—potentially exposing sensitive database data and even enabling remote code execution via the device’s operating system The Hacker News.
Vulnerability Details
Identified in FortiWeb versions:
- 7.6.0 through 7.6.3 (patched to 7.6.4+)
- 7.4.0 through 7.4.7 (patched to 7.4.8+)
- 7.2.0 through 7.2.10 (patched to 7.2.11+)
- 7.0.0 through 7.0.10 (patched to 7.0.11+)
Fortinet advises administrators to promptly update to the latest versions to remediate the vulnerability .
How It Works
The root cause lies in a function labeled get_fabric_user_by_token, part of the Fabric Connector feature—an integration interface between FortiWeb and other components of the Fortinet ecosystem. This function is invoked via three API endpoints:
/api/fabric/device/status/api/v[0-9]/fabric/widget/[a-z]+/api/v[0-9]/fabric/widget
A Bearer token sent in the Authorization HTTP header passes attacker-controlled input directly into an SQL query without sufficient sanitization. As a result, malicious actors can inject SQL commands. More alarmingly, by leveraging a SELECT … INTO OUTFILE statement, attackers may write and execute payloads via Python, achieving remote code execution as the mysql user.
Fix and Mitigation
Fortinet’s patch replaces the insecure string‑formatted SQL call with a prepared-statement-based approach, effectively neutralizing the injection vector
While applying patches is the most effective countermeasure, Fortinet suggests a temporary mitigation—disabling the HTTP/HTTPS administrative interface—to limit exposure until upgrades are in place.
Who Discovered It
The flaw was reported by Kentaro Kawane of GMO Cybersecurity. Kawane previously received acclaim for identifying critical Cisco Identity Services flaws (CVE‑2025‑20286, 2025‑20281, 2025‑20282), showcasing his expertise in uncovering high-impact vulnerabilities The Hacker News.
Historical Context
Fortinet has faced multiple high-profile breaches and vulnerability disclosures in recent years. In January 2025, configuration files and credentials from approximately 15,000 FortiGate devices were leaked due to another security flaw (CVE‑2022‑40684). Back in 2021, nearly half a million FortiGate VPN credentials were compromised due to CVE‑2018‑13379. This latest discovery underscores a recurring threat: attackers continue to exploit design weaknesses in Fortinet’s web-facing security products.
Why It Matters
- Unauthenticated access: Unlike vulnerabilities requiring valid logins, this flaw can be exploited by anyone with network access to the affected endpoints.
- High severity: A CVSS score of 9.6 indicates significant potential for host/system compromise.
- Remote code execution risk: The ability to write files via
SELECT … INTO OUTFILEamplifies risk, enabling each successful attack to escalate into full server compromise. - Integrated risk: FortiWeb sits at the intersection of web traffic and backend operations. A breach here could potentially compromise databases, dev resources, and other integrated systems.
Recommendations for Organizations
- Immediate Patch
Upgrade FortiWeb to 7.6.4+, 7.4.8+, 7.2.11+, or 7.0.11+, depending on your current version. Apply the update without delay. - Isolate Admin Interfaces
Restrict or disable HTTP/HTTPS access to the FortiWeb administrative interface until the patch is in place. - Monitor Logs
Scrutinize logs for unexpected API calls to the Fabric connector endpoints or unusual SQL errors, which could signal exploitation attempts. - Harden Fabric Integration
Audit the architectural structure of Fabric Connector deployments. Limit endpoint exposure and ensure least-privilege access where possible. - Broader Audit
Reassess your entire web application firewall deployment for outdated versions or misconfigurations that present similar risks.
Final Thoughts
This critical CVE‑2025‑25257 disclosure highlights the persistent challenge of securing integrated application firewall systems. Despite Fortinet’s strong reputation, successive exploits—spanning VPN, firewall device credentials, and now SQL injection—reveal an urgent need for constant vigilance and prompt remediation in organizational cybersecurity efforts.
If you manage a FortiWeb instance, immediate action is not just recommended—it’s essential. Patch now, restrict access, and resume vigilance. The layers of network defense that your systems rely on depend on swift remediation and proactive security posturing.
Please subscribe to the Newsletter so that you do not miss any critical update
