Path traversal in FortiWeb - CVE-2025-64446
Published: November 14, 2025 / Updated: April 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and execute arbitrary commands on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2025-64446
Links to Public Exploits and PoC-codes
- Exploit #12571 - CVE-2025-64446-PoC---FortiWeb-Path-Traversal (April 10, 2026)
- Exploit #12241 - CVE-2025-64446-FortiWeb-CGI-Bypass-PoC (January 4, 2026)
- Exploit #12187 - CVE-2025-64446_CVE-2025-58034 (December 12, 2025)
- Exploit #12152 - CVE-2025-64446 (November 28, 2025)
- Exploit #12151 - CVE-2025-64446-Exploit (November 28, 2025)
- Exploit #12146 - CVE-2025-64446 (November 28, 2025)
- Exploit #12134 - Fortinet FortiWeb unauthenticated RCE (November 25, 2025)