CyberSec.Space Logo
CVEブラウザに戻る

CVE-2025-58034

🔥 Known Exploited (CISA KEV)HIGH
7.2
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-11-18
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

Affected Platforms (CPE)

📦
Fortinet

Fortiweb

>= 7.0.0 and < 7.0.12>= 7.2.0 and < 7.2.12>= 7.4.0 and < 7.4.11>= 7.6.0 and < 7.6.6>= 8.0.0 and < 8.0.2

References & Advisories

関連する脆弱性情報