---
cve: "CVE-2025-25257"
severity: "CRITICAL"
cvss: 9.6
epss: "99.8%"
vendor: "Fortinet"
kev: true
exploited: true
published: "2025-07-17 16:15:34"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T03:08:42+02:00"
---

# CVE-2025-25257

> 9.6 CRITICAL · ⚠️ CISA KEV (414 Tage) · 🔓 Exploited

## Beschreibung

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-89** — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
  The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as…

## Angriffsmuster (CAPEC)

- [CAPEC-7 — Blind SQL Injection](https://capec.mitre.org/data/definitions/7.html) _(Severity: High)_
- [CAPEC-66 — SQL Injection](https://capec.mitre.org/data/definitions/66.html) _(Severity: High)_
- [CAPEC-108 — Command Line Execution through SQL Injection](https://capec.mitre.org/data/definitions/108.html) _(Severity: Very High)_
- [CAPEC-109 — Object Relational Mapping Injection](https://capec.mitre.org/data/definitions/109.html) _(Severity: High)_
- [CAPEC-110 — SQL Injection through SOAP Parameter Tampering](https://capec.mitre.org/data/definitions/110.html) _(Severity: Very High)_
- [CAPEC-470 — Expanding Control over the Operating System from the Database](https://capec.mitre.org/data/definitions/470.html) _(Severity: Very High)_

## Exploit-Evidenz

- [EDB-52473 — FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution](https://www.exploit-db.com/exploits/52473)

## Referenzen

- <https://fortiguard.fortinet.com/psirt/FG-IR-25-151>
- <https://packetstorm.news/files/id/210193/>
- <https://www.exploit-db.com/exploits/52473>
- <https://github.com/0xbigshaq/CVE-2025-25257>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25257>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-25257) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
