<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Multiple OS command injection in API and CLI</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-25-513</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2025-11-18T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2025-11-18T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2025-11-18T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An Improper Neutralization of Special Elements used in an OS Command (&#39;OS Command Injection&#39;) vulnerability [CWE-78] in FortiWeb may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.Fortinet has observed this to be exploited in the wild.FortiAppSec Cloud is NOT impacted by this vulnerability.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Execute unauthorized code or commands
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="4">
            None
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Discovered by Fortinet Threat intelligence with additional thanks to Jason McFadyen from Trend Research (Trend Micro).</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiWeb" Type="Product Name">
                <Branch Name="8.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-8.0.1">FortiWeb 8.0.1</FullProductName>
                </Branch>
                <Branch Name="8.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-8.0.0">FortiWeb 8.0.0</FullProductName>
                </Branch>
                <Branch Name="7.6.5" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.5">FortiWeb 7.6.5</FullProductName>
                </Branch>
                <Branch Name="7.6.4" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.4">FortiWeb 7.6.4</FullProductName>
                </Branch>
                <Branch Name="7.6.3" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.3">FortiWeb 7.6.3</FullProductName>
                </Branch>
                <Branch Name="7.6.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.2">FortiWeb 7.6.2</FullProductName>
                </Branch>
                <Branch Name="7.6.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.1">FortiWeb 7.6.1</FullProductName>
                </Branch>
                <Branch Name="7.6.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.0">FortiWeb 7.6.0</FullProductName>
                </Branch>
                <Branch Name="7.4.10" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.10">FortiWeb 7.4.10</FullProductName>
                </Branch>
                <Branch Name="7.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.9">FortiWeb 7.4.9</FullProductName>
                </Branch>
                <Branch Name="7.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.8">FortiWeb 7.4.8</FullProductName>
                </Branch>
                <Branch Name="7.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.7">FortiWeb 7.4.7</FullProductName>
                </Branch>
                <Branch Name="7.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.6">FortiWeb 7.4.6</FullProductName>
                </Branch>
                <Branch Name="7.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.5">FortiWeb 7.4.5</FullProductName>
                </Branch>
                <Branch Name="7.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.4">FortiWeb 7.4.4</FullProductName>
                </Branch>
                <Branch Name="7.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.3">FortiWeb 7.4.3</FullProductName>
                </Branch>
                <Branch Name="7.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.2">FortiWeb 7.4.2</FullProductName>
                </Branch>
                <Branch Name="7.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.1">FortiWeb 7.4.1</FullProductName>
                </Branch>
                <Branch Name="7.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.0">FortiWeb 7.4.0</FullProductName>
                </Branch>
                <Branch Name="7.2.11" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.11">FortiWeb 7.2.11</FullProductName>
                </Branch>
                <Branch Name="7.2.10" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.10">FortiWeb 7.2.10</FullProductName>
                </Branch>
                <Branch Name="7.2.9" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.9">FortiWeb 7.2.9</FullProductName>
                </Branch>
                <Branch Name="7.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.8">FortiWeb 7.2.8</FullProductName>
                </Branch>
                <Branch Name="7.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.7">FortiWeb 7.2.7</FullProductName>
                </Branch>
                <Branch Name="7.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.6">FortiWeb 7.2.6</FullProductName>
                </Branch>
                <Branch Name="7.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.5">FortiWeb 7.2.5</FullProductName>
                </Branch>
                <Branch Name="7.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.4">FortiWeb 7.2.4</FullProductName>
                </Branch>
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.3">FortiWeb 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.2">FortiWeb 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.1">FortiWeb 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.0">FortiWeb 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.11">FortiWeb 7.0.11</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.10">FortiWeb 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.9">FortiWeb 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.8">FortiWeb 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.7">FortiWeb 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.6">FortiWeb 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.5">FortiWeb 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.4">FortiWeb 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.3">FortiWeb 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.2">FortiWeb 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.1">FortiWeb 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.0">FortiWeb 7.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Multiple OS command injection in API and CLI</Title>
        <cvrf:CVE>CVE-2025-58034</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiWeb-8.0.1</ProductID>
                <ProductID>FortiWeb-8.0.0</ProductID>
                <ProductID>FortiWeb-7.6.5</ProductID>
                <ProductID>FortiWeb-7.6.4</ProductID>
                <ProductID>FortiWeb-7.6.3</ProductID>
                <ProductID>FortiWeb-7.6.2</ProductID>
                <ProductID>FortiWeb-7.6.1</ProductID>
                <ProductID>FortiWeb-7.6.0</ProductID>
                <ProductID>FortiWeb-7.4.10</ProductID>
                <ProductID>FortiWeb-7.4.9</ProductID>
                <ProductID>FortiWeb-7.4.8</ProductID>
                <ProductID>FortiWeb-7.4.7</ProductID>
                <ProductID>FortiWeb-7.4.6</ProductID>
                <ProductID>FortiWeb-7.4.5</ProductID>
                <ProductID>FortiWeb-7.4.4</ProductID>
                <ProductID>FortiWeb-7.4.3</ProductID>
                <ProductID>FortiWeb-7.4.2</ProductID>
                <ProductID>FortiWeb-7.4.1</ProductID>
                <ProductID>FortiWeb-7.4.0</ProductID>
                <ProductID>FortiWeb-7.2.11</ProductID>
                <ProductID>FortiWeb-7.2.10</ProductID>
                <ProductID>FortiWeb-7.2.9</ProductID>
                <ProductID>FortiWeb-7.2.8</ProductID>
                <ProductID>FortiWeb-7.2.7</ProductID>
                <ProductID>FortiWeb-7.2.6</ProductID>
                <ProductID>FortiWeb-7.2.5</ProductID>
                <ProductID>FortiWeb-7.2.4</ProductID>
                <ProductID>FortiWeb-7.2.3</ProductID>
                <ProductID>FortiWeb-7.2.2</ProductID>
                <ProductID>FortiWeb-7.2.1</ProductID>
                <ProductID>FortiWeb-7.2.0</ProductID>
                <ProductID>FortiWeb-7.0.11</ProductID>
                <ProductID>FortiWeb-7.0.10</ProductID>
                <ProductID>FortiWeb-7.0.9</ProductID>
                <ProductID>FortiWeb-7.0.8</ProductID>
                <ProductID>FortiWeb-7.0.7</ProductID>
                <ProductID>FortiWeb-7.0.6</ProductID>
                <ProductID>FortiWeb-7.0.5</ProductID>
                <ProductID>FortiWeb-7.0.4</ProductID>
                <ProductID>FortiWeb-7.0.3</ProductID>
                <ProductID>FortiWeb-7.0.2</ProductID>
                <ProductID>FortiWeb-7.0.1</ProductID>
                <ProductID>FortiWeb-7.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>6.7</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-25-513</URL>
                <Description>Multiple OS command injection in API and CLI</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>