NewsSecurity Vulnerabilities

Fortinet FortiWeb cgi_httpcontentrouting_post Directory Traversal Remote Code Execution Vulnerability (CVE-2025-25254)

CVE number = CVE-2025-25254

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiWeb.

Authentication is required to exploit this vulnerability.

The specific flaw exists within the cgi_httpcontentrouting_post function.

The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations.

An attacker can leverage this vulnerability to execute code in the context of root.

Further details – https://fortiguard.com/psirt/FG-IR-24-474

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.