CVE-2025-52970
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a specially crafted request.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:C
- EPSS probability
- 9.75%
- CWE
- CWE-233
- Published
- 2025-08-12
- Last modified
- 2026-03-13
Affected products
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiWeb
Weakness type
Related vulnerabilities
- CVE-2026-0515 — Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
- CVE-2026-32998 — This vulnerability in Veeam Service Provider Console allows for remote code execution.
- CVE-2026-33585 — Arqit SKA-Platform Improper Handling of Parameters Vulnerability
- CVE-2018-25233 — WebDrive 18.00.5057 Denial of Service via Secure WebDAV
- CVE-2026-2370 — Improper Handling of Parameters in GitLab
- CVE-2023-20514 — Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker...
- CVE-2025-55080 — Improper Parameter Check in ThreadX Syscall Implementation
- CVE-2025-55078 — Incomplete validation of kernel object pointers in system calls