CVE-2025-64471
A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to use the hash in place of the password to authenticate via crafted HTTP/HTTPS requests
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C
- EPSS probability
- 0.34%
- CWE
- CWE-836
- Published
- 2025-12-09
- Last modified
- 2026-03-12
Affected products
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiWeb
- Fortinet FortiWeb
Weakness type
Related vulnerabilities
- CVE-2026-44736 — OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects
- CVE-2026-9222 — Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication
- CVE-2026-40103 — Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds
- CVE-2019-25552 — CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Field
- CVE-2025-62618 — ELOG file upload stored XSS
- CVE-2025-52543 — Login to the application services using only the password hash
- CVE-2025-48925 — The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do...
- CVE-2023-39546 — CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe...