<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Path confusion vulnerability in GUI</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-25-910</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2025-11-14T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2025-11-14T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2025-11-14T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            A relative path traversal vulnerability [CWE-23] in FortiWeb may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.Fortinet has observed this to be exploited in the wildFortiAppSec Cloud is NOT impacted by this vulnerability.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Improper access control
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="4">
            None
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiWeb" Type="Product Name">
                <Branch Name="8.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-8.0.1">FortiWeb 8.0.1</FullProductName>
                </Branch>
                <Branch Name="8.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-8.0.0">FortiWeb 8.0.0</FullProductName>
                </Branch>
                <Branch Name="7.6.4" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.4">FortiWeb 7.6.4</FullProductName>
                </Branch>
                <Branch Name="7.6.3" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.3">FortiWeb 7.6.3</FullProductName>
                </Branch>
                <Branch Name="7.6.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.2">FortiWeb 7.6.2</FullProductName>
                </Branch>
                <Branch Name="7.6.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.1">FortiWeb 7.6.1</FullProductName>
                </Branch>
                <Branch Name="7.6.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.6.0">FortiWeb 7.6.0</FullProductName>
                </Branch>
                <Branch Name="7.4.9" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.9">FortiWeb 7.4.9</FullProductName>
                </Branch>
                <Branch Name="7.4.8" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.8">FortiWeb 7.4.8</FullProductName>
                </Branch>
                <Branch Name="7.4.7" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.7">FortiWeb 7.4.7</FullProductName>
                </Branch>
                <Branch Name="7.4.6" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.6">FortiWeb 7.4.6</FullProductName>
                </Branch>
                <Branch Name="7.4.5" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.5">FortiWeb 7.4.5</FullProductName>
                </Branch>
                <Branch Name="7.4.4" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.4">FortiWeb 7.4.4</FullProductName>
                </Branch>
                <Branch Name="7.4.3" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.3">FortiWeb 7.4.3</FullProductName>
                </Branch>
                <Branch Name="7.4.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.2">FortiWeb 7.4.2</FullProductName>
                </Branch>
                <Branch Name="7.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.1">FortiWeb 7.4.1</FullProductName>
                </Branch>
                <Branch Name="7.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.4.0">FortiWeb 7.4.0</FullProductName>
                </Branch>
                <Branch Name="7.2.11" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.11">FortiWeb 7.2.11</FullProductName>
                </Branch>
                <Branch Name="7.2.10" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.10">FortiWeb 7.2.10</FullProductName>
                </Branch>
                <Branch Name="7.2.9" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.9">FortiWeb 7.2.9</FullProductName>
                </Branch>
                <Branch Name="7.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.8">FortiWeb 7.2.8</FullProductName>
                </Branch>
                <Branch Name="7.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.7">FortiWeb 7.2.7</FullProductName>
                </Branch>
                <Branch Name="7.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.6">FortiWeb 7.2.6</FullProductName>
                </Branch>
                <Branch Name="7.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.5">FortiWeb 7.2.5</FullProductName>
                </Branch>
                <Branch Name="7.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.4">FortiWeb 7.2.4</FullProductName>
                </Branch>
                <Branch Name="7.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.3">FortiWeb 7.2.3</FullProductName>
                </Branch>
                <Branch Name="7.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.2">FortiWeb 7.2.2</FullProductName>
                </Branch>
                <Branch Name="7.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.1">FortiWeb 7.2.1</FullProductName>
                </Branch>
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.2.0">FortiWeb 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.0.11" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.11">FortiWeb 7.0.11</FullProductName>
                </Branch>
                <Branch Name="7.0.10" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.10">FortiWeb 7.0.10</FullProductName>
                </Branch>
                <Branch Name="7.0.9" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.9">FortiWeb 7.0.9</FullProductName>
                </Branch>
                <Branch Name="7.0.8" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.8">FortiWeb 7.0.8</FullProductName>
                </Branch>
                <Branch Name="7.0.7" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.7">FortiWeb 7.0.7</FullProductName>
                </Branch>
                <Branch Name="7.0.6" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.6">FortiWeb 7.0.6</FullProductName>
                </Branch>
                <Branch Name="7.0.5" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.5">FortiWeb 7.0.5</FullProductName>
                </Branch>
                <Branch Name="7.0.4" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.4">FortiWeb 7.0.4</FullProductName>
                </Branch>
                <Branch Name="7.0.3" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.3">FortiWeb 7.0.3</FullProductName>
                </Branch>
                <Branch Name="7.0.2" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.2">FortiWeb 7.0.2</FullProductName>
                </Branch>
                <Branch Name="7.0.1" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.1">FortiWeb 7.0.1</FullProductName>
                </Branch>
                <Branch Name="7.0.0" Type="Product Version">
                    <FullProductName ProductID="FortiWeb-7.0.0">FortiWeb 7.0.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Path confusion vulnerability in GUI</Title>
        <cvrf:CVE>CVE-2025-64446</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiWeb-8.0.1</ProductID>
                <ProductID>FortiWeb-8.0.0</ProductID>
                <ProductID>FortiWeb-7.6.4</ProductID>
                <ProductID>FortiWeb-7.6.3</ProductID>
                <ProductID>FortiWeb-7.6.2</ProductID>
                <ProductID>FortiWeb-7.6.1</ProductID>
                <ProductID>FortiWeb-7.6.0</ProductID>
                <ProductID>FortiWeb-7.4.9</ProductID>
                <ProductID>FortiWeb-7.4.8</ProductID>
                <ProductID>FortiWeb-7.4.7</ProductID>
                <ProductID>FortiWeb-7.4.6</ProductID>
                <ProductID>FortiWeb-7.4.5</ProductID>
                <ProductID>FortiWeb-7.4.4</ProductID>
                <ProductID>FortiWeb-7.4.3</ProductID>
                <ProductID>FortiWeb-7.4.2</ProductID>
                <ProductID>FortiWeb-7.4.1</ProductID>
                <ProductID>FortiWeb-7.4.0</ProductID>
                <ProductID>FortiWeb-7.2.11</ProductID>
                <ProductID>FortiWeb-7.2.10</ProductID>
                <ProductID>FortiWeb-7.2.9</ProductID>
                <ProductID>FortiWeb-7.2.8</ProductID>
                <ProductID>FortiWeb-7.2.7</ProductID>
                <ProductID>FortiWeb-7.2.6</ProductID>
                <ProductID>FortiWeb-7.2.5</ProductID>
                <ProductID>FortiWeb-7.2.4</ProductID>
                <ProductID>FortiWeb-7.2.3</ProductID>
                <ProductID>FortiWeb-7.2.2</ProductID>
                <ProductID>FortiWeb-7.2.1</ProductID>
                <ProductID>FortiWeb-7.2.0</ProductID>
                <ProductID>FortiWeb-7.0.11</ProductID>
                <ProductID>FortiWeb-7.0.10</ProductID>
                <ProductID>FortiWeb-7.0.9</ProductID>
                <ProductID>FortiWeb-7.0.8</ProductID>
                <ProductID>FortiWeb-7.0.7</ProductID>
                <ProductID>FortiWeb-7.0.6</ProductID>
                <ProductID>FortiWeb-7.0.5</ProductID>
                <ProductID>FortiWeb-7.0.4</ProductID>
                <ProductID>FortiWeb-7.0.3</ProductID>
                <ProductID>FortiWeb-7.0.2</ProductID>
                <ProductID>FortiWeb-7.0.1</ProductID>
                <ProductID>FortiWeb-7.0.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>9.4</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-25-910</URL>
                <Description>Path confusion vulnerability in GUI</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>