news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2025-64446

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
9.4 Critical
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
Risk score
100.0
Known exploited
CISA KEV
Published
2025-11-14
Status
Published

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Weaknesses

CWE-23

Coverage 1

Advisories and references