
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64447 is a cookie forgery vulnerability (CWE-565: Reliance on Cookies without Validation and Integrity Checking) in Fortinet FortiWeb that may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS requests using forged cookies. The vulnerability affects FortiWeb versions 7.0.0–7.0.11, 7.2.0–7.2.11, 7.4.0–7.4.10, 7.6.0–7.6.5, and 8.0.0–8.0.1; FortiAppSec Cloud is not impacted. It was publicly disclosed on December 9, 2025, and carries a CVSS v3.1 base score of 8.1 (High) per NVD, or 7.1 (High) per Fortinet's own advisory (FortiGuard Advisory, Feedly).
The root cause is insufficient validation and integrity checking of authentication cookies in FortiWeb's GUI component (CWE-565). An attacker who knows the target FortiWeb device's serial number can forge authentication cookies and submit crafted HTTP or HTTPS requests to execute arbitrary operations without any credentials. The serial number serves as the only prerequisite — no user interaction or elevated privileges are required. The vulnerability was internally discovered by the FortiWeb development team and also reported by Jason McFadyen of Trend Research under responsible disclosure. A proof-of-concept advisory has been published by the Zero Day Initiative (FortiGuard Advisory, ZDI Advisory).
Successful exploitation allows an unauthenticated remote attacker to perform privilege escalation and execute arbitrary operations on the affected FortiWeb system, impacting confidentiality, integrity, and availability. Since FortiWeb is a web application firewall, compromise could expose protected backend applications, allow manipulation of WAF policies, and potentially facilitate lateral movement into the broader network environment. The attack requires network access and prior knowledge of the device serial number but no user interaction (FortiGuard Advisory, Feedly).
A proof-of-concept exploit advisory was published by the Zero Day Initiative (ZDI-25-1094) on December 16, 2025, but there is no evidence of active in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and Fortinet's advisory confirms "Known Exploited: No." The EPSS score is approximately 0.071% (0.000710), indicating a currently low probability of exploitation in the near term. The attack complexity is rated High due to the requirement for prior knowledge of the FortiWeb serial number (ZDI Advisory, FortiGuard Advisory).
apachecookie_parse function (as referenced in public write-ups).Fortinet has released patched versions addressing CVE-2025-64447; administrators should upgrade to the following fixed releases: FortiWeb 8.0.2 or above, FortiWeb 7.6.6 or above, FortiWeb 7.4.11 or above, FortiWeb 7.2.12 or above, or FortiWeb 7.0.12 or above. FortiWeb 6.4 is not affected. As an interim measure, restrict management interface access to trusted IP addresses only and implement network segmentation to limit exposure of the FortiWeb admin GUI. No configuration-based workaround that fully mitigates the vulnerability has been published; upgrading is the recommended remediation (FortiGuard Advisory).
The vulnerability was reported to Fortinet by Jason McFadyen of Trend Research (Zero Day Initiative) under responsible disclosure, and ZDI published advisory ZDI-25-1094 on December 16, 2025. Check Point Research also published a defense advisory (CPAI-2025-11124) referencing this CVE. Community coverage has been limited but includes security aggregators and threat advisory platforms noting the PoC availability and the serial-number prerequisite as a partial mitigating factor (ZDI Advisory, FortiGuard Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."