
⚠ HIGH PRIORITY — CISA KEV. CVE-2025-25257 is an unauthenticated SQL injection in Fortinet FortiWeb WAF appliances. Attackers achieve remote code execution on Linux-based FortiWeb devices protecting public web applications.
Affected FortiWeb
- FortiWeb before 7.6.3
- FortiWeb before 7.4.7
- Internet-facing WAF on ports 443/8443
Check version
get system status
diagnose versionPatching Method
- Download fixed FortiWeb firmware from Fortinet support portal.
- Schedule maintenance — WAF will briefly stop filtering traffic during reboot.
- Install via System → Firmware → Upgrade in FortiWeb GUI.
- Reboot appliance; confirm version matches PSIRT fixed build table.
- Review WAF logs for SQLi payloads in last 30 days.
- Rotate FortiWeb admin passwords and API tokens.
get system status | grep Version
execute log filter category 0
execute log displayUntil patched
- Restrict FortiWeb management to OOB network
- Enable FortiGuard IPS signature if emergency mitigation published
- Assume compromise if internet-facing and unpatched