Use of hardcoded password for the redis service

Summary

A use of hard-coded credentials vulnerability [CWE-798] in the internal redis services in FortiWeb may allow an authenticated attacker with shell access to the device to connect to any running redis service and access its data

Version Affected Solution
FortiWeb 8.0 Not affected Not Applicable
FortiWeb 7.6 7.6.0 Upgrade to 7.6.1 or above
FortiWeb 7.4 7.4 all versions Migrate to a fixed release
FortiWeb 7.2 7.2 all versions Migrate to a fixed release
FortiWeb 7.0 7.0 all versions Migrate to a fixed release
FortiWeb 6.4 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Victor Pasman for reporting this vulnerability under responsible disclosure.

Timeline

2025-11-18: Initial publication