H-ISAC TLP White Threat Bulletin: Exploit Code Released for Fortinet FortiWeb Flaw CVE-2025-52970 - August 18, 2025

On August 12, 2025, FortiGuard Labs published an advisory for a flaw in FortiWeb tracked as CVE-2025-52970. Practical exploit code is now available for this flaw, increasing the possibility of attacks.

CVE-2025-52970 is an improper handling of parameters vulnerability in the FortiWeb web application firewall (WAF). This flaw allows an unauthenticated remote attacker to bypass authentication and gain administrative privileges. The attacker must possess non-public information pertaining to the device and the targeted user to exploit the vulnerability successfully. This suggests the attack requires some level of reconnaissance or insider knowledge. The CVSS score of the flaw is 7.7.

View the detailed bulletin below.

 

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272