CVE-2025-58034

Source
https://cve.org/CVERecord?id=CVE-2025-58034
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58034.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-58034
Published
2025-11-18T17:16:05.057Z
Modified
2026-03-13T03:37:14.099011Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58034.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "7.0.0"
            },
            {
                "fixed": "7.0.12"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.2.0"
            },
            {
                "fixed": "7.2.12"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.4.0"
            },
            {
                "fixed": "7.4.11"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "7.6.0"
            },
            {
                "fixed": "7.6.6"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "8.0.0"
            },
            {
                "fixed": "8.0.2"
            }
        ]
    }
]