
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66178 is an OS Command Injection vulnerability (CWE-78) in the Fortinet FortiWeb Web Application Firewall API that allows an authenticated attacker to execute arbitrary commands via a specially crafted HTTP request. It affects FortiWeb versions 7.0.0–7.0.12, 7.2.0–7.2.12, 7.4.0–7.4.11, 7.6.0–7.6.5, and 8.0.0–8.0.1. The vulnerability was disclosed on March 10, 2026, and was internally discovered and reported by Loic Pantano of Fortinet PSIRT. It carries a CVSSv3.1 base score of 7.2 (High) per NVD, or 6.7 (Medium) per Fortinet's own advisory (FortiGuard PSIRT, Red Hat CVE).
The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command) and resides specifically in the FortiWeb REST API component, particularly related to the web vulnerability scan (WVS) feature. An authenticated attacker can send a specially crafted HTTP request to the API that includes OS command injection payloads, which are not properly sanitized before being passed to the underlying operating system. Exploitation requires network access and high-privilege authentication (administrator-level credentials), but no user interaction is needed. No public proof-of-concept exploit code has been observed as of the time of disclosure (FortiGuard PSIRT).
Successful exploitation allows an authenticated attacker to execute arbitrary OS commands on the affected FortiWeb appliance, resulting in high confidentiality, integrity, and availability impact. This could lead to complete system compromise, including unauthorized access to sensitive configuration data, exfiltration of web application traffic or security policies, modification of WAF rules, and disruption of web application firewall operations. Given FortiWeb's role as a security gateway, compromise could undermine the security posture of all protected web applications behind it (FortiGuard PSIRT, Red Hat CVE).
As of the disclosure date, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.106%, indicating a low probability of exploitation in the near term. Exploitation requires authenticated access with high privileges, which significantly limits the attacker pool (FortiGuard PSIRT).
;, |, or backticks) in a parameter that is passed unsanitized to the OS.;, |, &&, backticks); unexpected command execution entries in system audit logs.curl, wget, nc).Fortinet has released patched versions for all affected branches: upgrade FortiWeb 7.0.x to 7.0.13 or later, 7.2.x to 7.2.13 or later, 7.4.x to 7.4.12 or later, 7.6.x to 7.6.7 or later, and 8.0.x to 8.0.3 or later. As a workaround where immediate patching is not possible, Fortinet recommends disabling the web vulnerability scan (WVS) feature via the CLI (config system feature-visibility; set wvs disable; end) and restricting REST API access using trusted host configurations to limit exposure to authorized IP addresses only. Additionally, organizations should enforce least-privilege access controls and monitor FortiWeb logs for suspicious API activity (FortiGuard PSIRT).
Coverage of CVE-2025-66178 has been limited, consistent with its medium severity rating and lack of public exploit code. CyberHub Blog noted it as part of a broader roundup of multiple vulnerabilities discovered in Fortinet products, and the disclosure was shared on Bluesky by the same outlet. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation (CyberHub Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."