CVE-2025-64471: 
Fortinet FortiWeb vulnerability analysis and mitigation

Overview

CVE-2025-64471 is a "Use of Password Hash Instead of Password for Authentication" (CWE-836) vulnerability in Fortinet FortiWeb that may allow an unauthenticated attacker to use a captured password hash in place of the actual password to authenticate via crafted HTTP/HTTPS requests. It affects FortiWeb versions 8.0.0–8.0.1, 7.6.0–7.6.5, 7.4.0–7.4.10, 7.2.0–7.2.11, and 7.0.0–7.0.11; FortiWeb 6.4 is not affected. The vulnerability was internally discovered and reported by the FortiWeb development team, with initial publication on December 9, 2025. Fortinet's official advisory assigns a CVSSv3 score of 4.4 (Medium), while NVD rates it 7.5 (High) (FortiGuard Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-836 (Use of Password Hash Instead of Password for Authentication), a "pass-the-hash" style flaw in FortiWeb's GUI authentication component. The authentication mechanism improperly accepts a password hash value directly in place of the plaintext password when processing crafted HTTP/HTTPS requests, bypassing the intended credential verification step. An attacker who has previously obtained a valid user's password hash — for example, through a separate credential theft or database exposure — can replay that hash to authenticate without knowing the actual password. The attack vector is network-based, requires no user interaction, and no privileges are needed to initiate the exploit, though obtaining the hash itself is a prerequisite (FortiGuard Advisory).

Impact

Successful exploitation allows an attacker to authenticate to the FortiWeb management interface without knowing the legitimate user's password, effectively bypassing authentication controls. Fortinet classifies the impact as "Escalation of Privilege," meaning an attacker could gain unauthorized administrative or elevated access to the FortiWeb web application firewall. This could enable modification of WAF policies, interception or manipulation of protected web traffic, and potential lateral movement into backend systems that FortiWeb is configured to protect. The integrity impact is rated High, with no direct confidentiality or availability impact from the vulnerability itself (FortiGuard Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (FortiGuard Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.023% (0.000230), indicating a very low current probability of exploitation in the wild (Feedly). No threat actor attribution has been reported. Exploitation requires prior acquisition of a valid password hash, which raises the practical bar for attackers.

Exploitation steps

  1. Obtain a password hash: Acquire a valid FortiWeb user's password hash through a prior compromise — e.g., credential database theft, memory scraping, or network interception of an authentication exchange.
  2. Identify target: Locate internet-facing or network-accessible FortiWeb management interfaces (typically HTTPS on port 443 or 8443) running affected versions (7.0.0–7.0.11, 7.2.0–7.2.11, 7.4.0–7.4.10, 7.6.0–7.6.5, or 8.0.0–8.0.1).
  3. Craft malicious HTTP/HTTPS request: Construct an authentication request to the FortiWeb GUI login endpoint, substituting the password field with the captured hash value rather than the plaintext password.
  4. Authenticate as the target user: Submit the crafted request; the vulnerable authentication logic accepts the hash as valid credentials, granting session access with the privileges of the targeted account.
  5. Achieve objective: With authenticated access, modify WAF rules, exfiltrate configuration data, or use the FortiWeb management plane as a pivot point for further actions against protected backend systems (FortiGuard Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTPS authentication requests to the FortiWeb management interface from unexpected source IPs; authentication attempts where the credential format does not match typical plaintext password patterns.
  • Logs: FortiWeb authentication logs showing successful logins from IP addresses not associated with known administrators; login events at unusual times or from geographic locations inconsistent with normal usage.
  • Behavioral: Unexpected changes to WAF policies, server pool configurations, or administrative user accounts following a login event; new admin accounts created or existing accounts modified shortly after an anomalous authentication.

Mitigation and workarounds

Fortinet has released patched versions addressing this vulnerability. Administrators should upgrade to the following versions or later: FortiWeb 8.0.2+, FortiWeb 7.6.6+, FortiWeb 7.4.11+, FortiWeb 7.2.12+, or FortiWeb 7.0.12+. FortiWeb 6.4 is not affected and requires no action. As interim mitigations, restrict network access to the FortiWeb management interface to trusted IP ranges only, monitor authentication logs for anomalous login activity, and rotate all FortiWeb administrative credentials in case hashes have been previously exposed (FortiGuard Advisory).

Community reactions

BleepingComputer covered the disclosure as part of broader reporting on Fortinet's December 2025 advisories addressing critical FortiCloud SSO and FortiWeb authentication bypass flaws (BleepingComputer). ThaiCERT and other national CERTs issued advisories noting the authentication bypass risk across multiple Fortinet products. Community reaction has been moderate, with security aggregators such as BeyondMachines and Rewterz flagging the vulnerability in threat digests. No significant researcher controversy or independent technical write-ups have emerged, consistent with the absence of a public PoC.

Additional resources


Source: This report was generated using AI

Related Fortinet FortiWeb vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-26035CRITICAL9.8
  • Fortinet FortiWeb logoFortinet FortiWeb
  • cpe:2.3:a:fortinet:fortiweb
NoYesAug 12, 2026
CVE-2026-40688HIGH7.2
  • Fortinet FortiWeb logoFortinet FortiWeb
  • cpe:2.3:a:fortinet:fortiweb
NoYesApr 14, 2026
CVE-2026-39814MEDIUM6.7
  • Fortinet FortiWeb logoFortinet FortiWeb
  • cpe:2.3:a:fortinet:fortiweb
NoYesApr 14, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NoYesAug 12, 2026
CVE-2026-39811MEDIUM4.9
  • Fortinet FortiWeb logoFortinet FortiWeb
  • cpe:2.3:a:fortinet:fortiweb
NoYesApr 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management