Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-58034

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.046
EPSS Ranking 88.1%
CVSS Severity
CVSS v3 Score 7.2
Proposed Action
Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.
Ransomware Campaign
Unknown
Products affected by CVE-2025-58034


Contact Us

Shodan ® - All rights reserved