A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker with shell access to the device to connect to redis service and access its data
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-843 | Vendor Advisory |
Configurations
History
20 Nov 2025, 14:36
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:* | |
| First Time |
Fortinet fortiweb
Fortinet |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-25-843 - Vendor Advisory |
18 Nov 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-18 17:16
Updated : 2025-11-20 14:36
NVD link : CVE-2025-59669
Mitre link : CVE-2025-59669
CVE.ORG link : CVE-2025-59669
JSON object : View
Products Affected
fortinet
- fortiweb
CWE
CWE-798
Use of Hard-coded Credentials
