PoC Index

CVE-2025-64446

KEVCRITICAL 9.8EPSS 91.8%

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
91.84% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2025-11-14
Nuclei
critical · CWE-23
Published
2025-11-14
Updated
2026-02-26

Proof-of-concept exploits (11)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (2)

References

Related