CVE-2025-66178: 
Fortinet FortiWeb vulnerability analysis and mitigation

Overview

CVE-2025-66178 is an OS Command Injection vulnerability (CWE-78) in the Fortinet FortiWeb Web Application Firewall API that allows an authenticated attacker to execute arbitrary commands via a specially crafted HTTP request. It affects FortiWeb versions 7.0.0–7.0.12, 7.2.0–7.2.12, 7.4.0–7.4.11, 7.6.0–7.6.5, and 8.0.0–8.0.1. The vulnerability was disclosed on March 10, 2026, and was internally discovered and reported by Loic Pantano of Fortinet PSIRT. It carries a CVSSv3.1 base score of 7.2 (High) per NVD, or 6.7 (Medium) per Fortinet's own advisory (FortiGuard PSIRT, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command) and resides specifically in the FortiWeb REST API component, particularly related to the web vulnerability scan (WVS) feature. An authenticated attacker can send a specially crafted HTTP request to the API that includes OS command injection payloads, which are not properly sanitized before being passed to the underlying operating system. Exploitation requires network access and high-privilege authentication (administrator-level credentials), but no user interaction is needed. No public proof-of-concept exploit code has been observed as of the time of disclosure (FortiGuard PSIRT).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary OS commands on the affected FortiWeb appliance, resulting in high confidentiality, integrity, and availability impact. This could lead to complete system compromise, including unauthorized access to sensitive configuration data, exfiltration of web application traffic or security policies, modification of WAF rules, and disruption of web application firewall operations. Given FortiWeb's role as a security gateway, compromise could undermine the security posture of all protected web applications behind it (FortiGuard PSIRT, Red Hat CVE).

Exploitability

As of the disclosure date, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.106%, indicating a low probability of exploitation in the near term. Exploitation requires authenticated access with high privileges, which significantly limits the attacker pool (FortiGuard PSIRT).

Exploitation steps

  1. Reconnaissance: Identify FortiWeb appliances exposed to the network (management interface or REST API endpoint) running affected versions (7.0.0–7.0.12, 7.2.0–7.2.12, 7.4.0–7.4.11, 7.6.0–7.6.5, or 8.0.0–8.0.1) using network scanning or Shodan.
  2. Obtain credentials: Acquire valid high-privilege (administrator) credentials for the FortiWeb management interface or REST API through phishing, credential stuffing, or other means.
  3. Authenticate to the REST API: Log in to the FortiWeb REST API using the obtained credentials to obtain a valid session token.
  4. Craft malicious HTTP request: Construct a specially crafted HTTP request targeting the vulnerable API endpoint (associated with the web vulnerability scan feature) that embeds OS command injection payloads (e.g., using shell metacharacters such as ;, |, or backticks) in a parameter that is passed unsanitized to the OS.
  5. Execute arbitrary commands: Submit the crafted request; the injected commands execute on the underlying OS with the privileges of the FortiWeb service, enabling actions such as spawning a reverse shell, exfiltrating configuration files, or modifying WAF policies (FortiGuard PSIRT).

Indicators of compromise

  • Network: Unusual or unexpected REST API calls to FortiWeb management endpoints, particularly those associated with the web vulnerability scan (WVS) feature, from unauthorized or unexpected source IPs.
  • Logs: FortiWeb system logs showing API requests with anomalous parameter values containing shell metacharacters (;, |, &&, backticks); unexpected command execution entries in system audit logs.
  • Process: Unexpected child processes spawned by the FortiWeb service process (e.g., shell interpreters, network utilities like curl, wget, nc).
  • File System: Unexpected new files, scripts, or binaries created in FortiWeb system directories; modifications to WAF policy or configuration files outside of normal change windows.
  • Network: Outbound connections from the FortiWeb appliance to unknown external IP addresses or unusual ports, potentially indicating reverse shell activity (FortiGuard PSIRT).

Mitigation and workarounds

Fortinet has released patched versions for all affected branches: upgrade FortiWeb 7.0.x to 7.0.13 or later, 7.2.x to 7.2.13 or later, 7.4.x to 7.4.12 or later, 7.6.x to 7.6.7 or later, and 8.0.x to 8.0.3 or later. As a workaround where immediate patching is not possible, Fortinet recommends disabling the web vulnerability scan (WVS) feature via the CLI (config system feature-visibility; set wvs disable; end) and restricting REST API access using trusted host configurations to limit exposure to authorized IP addresses only. Additionally, organizations should enforce least-privilege access controls and monitor FortiWeb logs for suspicious API activity (FortiGuard PSIRT).

Community reactions

Coverage of CVE-2025-66178 has been limited, consistent with its medium severity rating and lack of public exploit code. CyberHub Blog noted it as part of a broader roundup of multiple vulnerabilities discovered in Fortinet products, and the disclosure was shared on Bluesky by the same outlet. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation (CyberHub Blog).

Additional resources


Source: This report was generated using AI

Related Fortinet FortiWeb vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-26035CRITICAL9.8
  • Fortinet FortiWeb logoFortinet FortiWeb
  • cpe:2.3:a:fortinet:fortiweb
NoYesAug 12, 2026
CVE-2026-40688HIGH7.2
  • Fortinet FortiWeb logoFortinet FortiWeb
  • cpe:2.3:a:fortinet:fortiweb
NoYesApr 14, 2026
CVE-2026-39814MEDIUM6.7
  • Fortinet FortiWeb logoFortinet FortiWeb
  • cpe:2.3:a:fortinet:fortiweb
NoYesApr 14, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NoYesAug 12, 2026
CVE-2026-39811MEDIUM4.9
  • Fortinet FortiWeb logoFortinet FortiWeb
  • cpe:2.3:a:fortinet:fortiweb
NoYesApr 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management