A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker with shell access to the device to connect to redis service and access its data
History

Thu, 20 Nov 2025 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

Tue, 18 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Description A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker with shell access to the device to connect to redis service and access its data
First Time appeared Fortinet
Fortinet fortiweb
Weaknesses CWE-798
CPEs cpe:2.3:a:fortinet:fortiweb:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.12:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.12:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.2.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.10:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.11:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.4:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.5:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.6:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.7:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.8:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.4.9:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:7.6.0:*:*:*:*:*:*:*
Vendors & Products Fortinet
Fortinet fortiweb
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:U/RC:R'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2025-11-18T17:01:19.617Z

Updated: 2025-11-18T19:34:51.604Z

Reserved: 2025-09-18T15:35:02.492Z

Link: CVE-2025-59669

cve-icon Vulnrichment

Updated: 2025-11-18T19:34:47.693Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-18T17:16:07.390

Modified: 2025-11-20T14:36:53.967

Link: CVE-2025-59669

cve-icon Redhat

No data.