
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64471 is a "Use of Password Hash Instead of Password for Authentication" (CWE-836) vulnerability in Fortinet FortiWeb that may allow an unauthenticated attacker to use a captured password hash in place of the actual password to authenticate via crafted HTTP/HTTPS requests. It affects FortiWeb versions 8.0.0–8.0.1, 7.6.0–7.6.5, 7.4.0–7.4.10, 7.2.0–7.2.11, and 7.0.0–7.0.11; FortiWeb 6.4 is not affected. The vulnerability was internally discovered and reported by the FortiWeb development team, with initial publication on December 9, 2025. Fortinet's official advisory assigns a CVSSv3 score of 4.4 (Medium), while NVD rates it 7.5 (High) (FortiGuard Advisory, Red Hat CVE).
The root cause is classified as CWE-836 (Use of Password Hash Instead of Password for Authentication), a "pass-the-hash" style flaw in FortiWeb's GUI authentication component. The authentication mechanism improperly accepts a password hash value directly in place of the plaintext password when processing crafted HTTP/HTTPS requests, bypassing the intended credential verification step. An attacker who has previously obtained a valid user's password hash — for example, through a separate credential theft or database exposure — can replay that hash to authenticate without knowing the actual password. The attack vector is network-based, requires no user interaction, and no privileges are needed to initiate the exploit, though obtaining the hash itself is a prerequisite (FortiGuard Advisory).
Successful exploitation allows an attacker to authenticate to the FortiWeb management interface without knowing the legitimate user's password, effectively bypassing authentication controls. Fortinet classifies the impact as "Escalation of Privilege," meaning an attacker could gain unauthorized administrative or elevated access to the FortiWeb web application firewall. This could enable modification of WAF policies, interception or manipulation of protected web traffic, and potential lateral movement into backend systems that FortiWeb is configured to protect. The integrity impact is rated High, with no direct confidentiality or availability impact from the vulnerability itself (FortiGuard Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (FortiGuard Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.023% (0.000230), indicating a very low current probability of exploitation in the wild (Feedly). No threat actor attribution has been reported. Exploitation requires prior acquisition of a valid password hash, which raises the practical bar for attackers.
Fortinet has released patched versions addressing this vulnerability. Administrators should upgrade to the following versions or later: FortiWeb 8.0.2+, FortiWeb 7.6.6+, FortiWeb 7.4.11+, FortiWeb 7.2.12+, or FortiWeb 7.0.12+. FortiWeb 6.4 is not affected and requires no action. As interim mitigations, restrict network access to the FortiWeb management interface to trusted IP ranges only, monitor authentication logs for anomalous login activity, and rotate all FortiWeb administrative credentials in case hashes have been previously exposed (FortiGuard Advisory).
BleepingComputer covered the disclosure as part of broader reporting on Fortinet's December 2025 advisories addressing critical FortiCloud SSO and FortiWeb authentication bypass flaws (BleepingComputer). ThaiCERT and other national CERTs issued advisories noting the authentication bypass risk across multiple Fortinet products. Community reaction has been moderate, with security aggregators such as BeyondMachines and Rewterz flagging the vulnerability in threat digests. No significant researcher controversy or independent technical write-ups have emerged, consistent with the absence of a public PoC.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."