A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
Is CVE-2025-64446 exploited?
Listed in the CISA KEV catalog on 2025-11-14.
Federal remediation due 2025-11-21.
Past that date by 267 days.
EPSS puts exploitation in the next 30 days at 92%.
Public exploit code: packaged in a public tool.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2025-64446
PlainSec has not published a story about this CVE.