CVE-2025-48840
EUVD-2025-20848610.03.2026, 18:17
An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a specially crafted request.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortiweb | 7.0.0 ≤ 𝑥 < 7.4.9 |
| fortinet | fortiweb | 7.6.0 ≤ 𝑥 < 7.6.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
Vulnerability Media Exposure