---
cve: "CVE-2025-53609"
severity: "MEDIUM"
cvss: 4.7
epss: "8.9%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2025-09-09 14:15:46"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T16:06:02+02:00"
---

# CVE-2025-53609

> 4.7 MEDIUM

## Beschreibung

A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:P/RL:X/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-23** — Relative Path Traversal
  The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

## Angriffsmuster (CAPEC)

- [CAPEC-76 — Manipulating Web Input to File System Calls](https://capec.mitre.org/data/definitions/76.html) _(Severity: Very High)_
- [CAPEC-139 — Relative Path Traversal](https://capec.mitre.org/data/definitions/139.html) _(Severity: High)_

## Referenzen

- <https://fortiguard.fortinet.com/psirt/FG-IR-25-512>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-53609) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
