Command injection in CLI command

Summary

A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in FortiWeb CLI may allow a privileged attacker to execute arbitrary code or command via crafted CLI commands.

Version Affected Solution
FortiWeb 8.0 Not affected Not Applicable
FortiWeb 7.6 7.6.0 through 7.6.3 Upgrade to 7.6.4 or above
FortiWeb 7.4 7.4.1 through 7.4.8 Upgrade to 7.4.9 or above
FortiWeb 7.2 Not affected Not Applicable
FortiWeb 7.0 Not affected Not Applicable
FortiWeb 6.4 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Kentaro Kawane from GMO Cybersecurity by Ierae for reporting this vulnerability under responsible disclosure.

Timeline

2025-08-12: Initial publication