vulnti.work

Fortinet FortiWeb OS Command Injection Vulnerability

High Listed in CISA KEV
CVECVE-2025-58034
First seen2025-11-18 00:00 UTC
Disclosed2025-11-18 00:00 UTC
Last updated2026-07-14 20:15 UTC
Channel statuspending_review

Summary

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • Fortinet:FortiWeb

Sources

  • CISA KEV DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV