Fortinet FortiWeb OS Command Injection Vulnerability
High Listed in CISA KEV
Summary
Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Fortinet:FortiWeb
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2025-58034 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://fortiguard.fortinet.com/psirt/FG-IR-25-513 reference
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV