Relative path traversal in FortiWeb - CVE-2025-53609

 

Relative path traversal in FortiWeb - CVE-2025-53609

Published: September 9, 2025


Vulnerability identifier: #VU115082
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-53609
CWE-ID: CWE-23
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to gain access to sensitive information.

The vulnerability exists due to relative path traversal in policy scripting. An authenticated attacker can perform an arbitrary file read on the underlying system via crafted requests.


Affected software

FortiWeb

How to mitigate CVE-2025-53609

Install update from vendor's website.

FortiWeb - addressed in versions 7.2.12, 7.4.9, 7.6.5

External References

Related Security Bulletins