CVE-2025-25257 is a critical unauthenticated SQL injection vulnerability affecting Fortinet FortiWeb appliances. Exploiting improperly sanitized user inputs in the administrative API, attackers can execute arbitrary SQL commands via the HTTP/HTTPS interface without authentication. The SQL injection can be escalated to Remote Code Execution (RCE) by writing malicious files to the underlying system. Public proof-of-concept (PoC) exploit code is available, and immediate patching is strongly recommended to prevent exploitation.
Get through updates and upcoming events, and more directly in your inbox