CVE-2025-66178
CVE-2025-66178: 1 tracked advisory record across Fortinet. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Fortinet
1 advisory- Advisory severityMedium6.7
Medium [CVE-2025-66178] improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb…
CVE-2025-66178Source published Source updated
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow an authenticated attacked to execute arbitrary commands via a specialy crafted HTTP request.
- Related products — impact not confirmed
- FortiWeb
- Source-reported affected versions
- FortiWeb 8.0: 8.0.0 through 8.0.1
- FortiWeb 7.6: 7.6.0 through 7.6.5
- FortiWeb 7.4: 7.4.0 through 7.4.11
- FortiWeb 7.2: 7.2.0 through 7.2.12
1 more entries in the full advisory.
- Source-reported fixed versions
- FortiWeb 8.0: 8.0.3
- FortiWeb 7.6: 7.6.7
- FortiWeb 7.4: 7.4.12
- FortiWeb 7.2: 7.2.13
1 more entries in the full advisory.
- Mitigation guidance
- Upgrade per the Affected/Solution table: FortiWeb 8.0: 8.0.3; FortiWeb 7.6: 7.6.7; FortiWeb 7.4: 7.4.12; FortiWeb 7.2: 7.2.13; FortiWeb 7.0: 7.0.13.
Android app · Google Play
Monitor future Fortinet CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.