Use of Password Hash Instead of Password for Authentication in FortiWeb - CVE-2025-64471

 

Use of Password Hash Instead of Password for Authentication in FortiWeb - CVE-2025-64471

Published: December 9, 2025


Vulnerability identifier: #VU119440
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-64471
CWE-ID: CWE-836
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to manipulate data.

The vulnerability exists due to use of password hash instead of password for authentication. An unauthenticated attacker can use the hash in place of the password to authenticate via crafted HTTP/HTTPS requests.


Affected software

FortiWeb

How to mitigate CVE-2025-64471

Install update from vendor's website.

FortiWeb - addressed in versions 7.0.12, 7.2.12, 7.4.11, 7.6.6, 8.0.2

External References

Related Security Bulletins