LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-58034: Fortinet FortiWeb OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 18, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 25, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-58034 to its Known Exploited Vulnerabilities catalog on Nov 18, 2025, with a federal patch deadline of Nov 25, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI…

CVE-2025-58034 is an OS command injection vulnerability in Fortinet FortiWeb. An authenticated attacker can send crafted HTTP requests or CLI commands that cause the product to run unauthorized commands on the underlying operating system. Because FortiWeb sits at the edge as a web application firewall, successful abuse can give an attacker a foothold on a security appliance that often holds privileged network position and sensitive configuration data.

Defenders should treat this as a high-priority issue for any FortiWeb deployment. Confirm exact affected versions, fixed releases, and any configuration prerequisites against the official Fortinet advisory; public detail beyond the CISA summary is limited.

How it works

The flaw is classified as CWE-78 (OS Command Injection). In products of this class, user-controlled input reaches a shell or system command without proper sanitization or parameterization. Here, an attacker who already has valid credentials can supply specially crafted HTTP requests or CLI commands. Those inputs are then interpreted by the FortiWeb process as operating-system commands, allowing arbitrary code execution with the privileges of the FortiWeb service.

No public exploit code or detailed attack chain is provided in the available facts. The essential requirement is authentication; unauthenticated remote exploitation is not described. Once code execution is achieved, an attacker can typically install persistence, pivot, or alter WAF policies. Specific payload formats and exact injection points must be verified against the vendor advisory.

Am I affected? How to find it in your systems

FortiWeb appliances and virtual instances commonly run as reverse proxies or inline web application firewalls protecting HTTP/HTTPS applications, often in DMZs or cloud edge environments. Inventory every FortiWeb device (hardware, VM, or cloud-hosted) by querying management interfaces, CMDB records, or network discovery tools that fingerprint Fortinet products.

If version information is unavailable or the advisory is unclear, treat the device as potentially vulnerable until confirmed otherwise.

How to remediate

Apply the vendor-supplied update that addresses CVE-2025-58034 as soon as it can be tested and deployed. Follow Fortinet’s installation and reboot guidance exactly. After patching, verify the new version string and re-validate that administrative access still functions as expected.

CISA guidance also notes that organizations should apply mitigations per vendor instructions, follow BOD 22-01 for cloud services where applicable, or discontinue use if no mitigations exist.

If you can't patch immediately

Until the official update can be installed, reduce the attack surface and increase detection capability.

These steps do not eliminate the vulnerability; they only lower the likelihood of successful exploitation until the patch is applied.

If your data may have been exposed

Actively exploited command-injection flaws on edge security devices frequently lead to full compromise of the appliance and subsequent lateral movement or data theft. Although ransomware use of this specific CVE is not documented, treat any confirmed exploitation as a potential breach. Rotate credentials that were stored on or used by the FortiWeb, review WAF policy changes, and examine downstream application logs for signs of further compromise. Organizations can also run a free exposure scan of their email addresses against known breach data sets to determine whether related accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · FortiWeb
WeaknessCWE-78
Added to CISA KEVNov 18, 2025
Federal patch deadlineNov 25, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities