{"id":11515,"date":"2025-07-14T12:54:06","date_gmt":"2025-07-14T05:54:06","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=11515"},"modified":"2026-06-25T10:01:40","modified_gmt":"2026-06-25T03:01:40","slug":"fortinet-patch-severe-injection-sql-infortiweb-cve-2025-25257","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/en\/2025\/07\/14\/fortinet-patch-severe-injection-sql-infortiweb-cve-2025-25257\/","title":{"rendered":"Fortinet Patch Severe Injection SQL InfortiWeb (CVE &#8211; 2025-25257)"},"content":{"rendered":"<p><b>Fortinet recently released a patch for the CVE-2025-25257 vulnerability in its FortiWeb product. The vulnerability, scored 9.6\/10 on the CVSS scale, allows unauthenticated hackers to execute malicious SQL commands remotely and may even hijack the system if not handled in time.<\/b><\/p>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper js-lbImage\" title=\"1752483170886.png\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\" data-single-image=\"1\" data-src=\"https:\/\/whitehat.vn\/attachments\/1752483170886-png.17304\/\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1752483170886.png\" src=\"https:\/\/whitehat.vn\/attachments\/1752483170886-png.17304\/\" alt=\"1752483170886.png\" width=\"728\" height=\"380\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<p>The vulnerability stems from a function called get_fabric_user_by_token in the Fabric Connector component \u2013 which is responsible for connecting FortiWeb to other Fortinet products.<\/p>\n<p>The error belongs to the SQL Injection group (CWE &#8211; 89) \u2013 a common but extremely dangerous error that exists at the API level. When FortiWeb receives an HTTP request with a Bearer token in the header. The system will call the get construct user by token, then fabric access check.<\/p>\n<p>Data from this token is not properly checked and sanitized but is still fed directly into the SQL query.<\/p>\n<p>The result: hackers can write and execute arbitrary SQL commands on their own, even without even logging into the system.<\/p>\n<p>Particularly dangerous: If a SQL instruction is incorporated such as SELECT&#8230; INTO OUTFILE, hackers can write a malicious file to the system (e.g., a Python script), then execute it to gain access \u2013 from SQUL Injection to Remote Code Execution (RCE).<\/p>\n<p>The following FortiWeb versions are all affected:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">7.6.0 7.7.3 Update to 7.4<\/li>\n<li data-xf-list-type=\"ul\">7.4.0 7.3.7 Update to 7.8<\/li>\n<li data-xf-list-type=\"ul\">7.2.0 7.1.1 Updated to 7.0.11<\/li>\n<li data-xf-list-type=\"ul\">7.0.0 7.1.1 Update to 7.O.11<\/li>\n<\/ul>\n<p>Fortinet replaced dangerous SQL queries with prepared statements in the patch. SQL Injection does not require authentication, which means hackers can exploit it without a system account.<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Easily attacked endpoint APIs include:\n<ul>\n<li data-xf-list-type=\"ul\">\/ api\/fabric\/device\/status<\/li>\n<li data-xf-list-type=\"ul\">\/api\/v[0-9]\/fabric\/widget\/<\/li>\n<\/ul>\n<\/li>\n<li data-xf-list-type=\"ul\">If the organization&#8217;s FortiWeb system is opening the HTTP\/HTTpS administration interface to the internet, the risk of remote exploitation is very high.<\/li>\n<\/ul>\n<p>Recommended solutions:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Update the patch immediately to the correct version of FortiWeb.<\/li>\n<li data-xf-list-type=\"ul\">While waiting for updates, disable the HTTP\/HTTpS administration interface if not necessary &#8211; this is the primary route of attack.<\/li>\n<li data-xf-list-type=\"ul\">Check system logs and SQL queries for signs of exploitation.<\/li>\n<li data-xf-list-type=\"ul\">Apply the &#8220;least privilege&#8221; principle to users and services, limiting the file permissions of the server&#8217;s user account if possible.<\/li>\n<li data-xf-list-type=\"ul\">Regularly evaluating API security, due to endpoints APids are increasingly targeted by hackers.<\/li>\n<\/ul>\n<p>FortiWeb is no longer &#8220;invulnerable fortress&#8221;. This incident is a wake &#8211; up call that even security devices are not immune to risk. A small programming error such as a lack of input checks can throw open the door to hackers.<\/p>\n<p>Given its high severity, large scope of impact, and easy exploitation, organizations using FortiWeb need to take immediate action to patch errors, test systems, and tighten access controls.<\/p>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/fortinet-va-lo-hong-sql-injection-nghiem-trong-tren-fortiweb-cve-2025-25257.18559\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/fortinet-va-lo-hong-sql-injection-nghiem-trong-tren-fortiweb-cve-2025-25257.18559\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Fortinet recently released a patch for the CVE-2025-25257 vulnerability in its FortiWeb product. The vulnerability, scored 9.6\/10 on the CVSS scale, allows unauthenticated hackers to execute malicious SQL commands remotely and may even hijack the system if not handled in time. The vulnerability stems from a function called get_fabric_user_by_token in the Fabric Connector component \u2013 [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[351],"tags":[],"class_list":["post-11515","post","type-post","status-publish","format-standard","hentry","category-news-announcements"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11515","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=11515"}],"version-history":[{"count":1,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11515\/revisions"}],"predecessor-version":[{"id":11516,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11515\/revisions\/11516"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=11515"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=11515"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=11515"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}