AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-64447

HIGH · CVSS 8.1 EPSS 7.65%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-12-09 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.1. It affects Fortinet. Exploitation may require the attacker to be authenticated.

CVE
CVE-2025-64447
Severity
HIGH
CVSS
8.1
EPSS
7.65%
Fortinet

Original NVD Description

A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS request via forged cookies, requiring prior knowledge of the FortiWeb serial number.

Related CVEs

Other vulnerabilities affecting the same vendor(s)