Cyber Security News

Fortinet FortiWeb Instances Hacked With Webshells Following Public PoC Exploits

Dozens of Fortinet FortiWeb instances have been compromised with webshells in a widespread hacking campaign, according to the threat monitoring organization The Shadowserver Foundation.

The attacks are linked to a critical vulnerability, tracked as CVE-2025-25257, for which public proof-of-concept (PoC) exploits were released just days ago.

Key Takeaways
1. A critical flaw in Fortinet FortiWeb is being actively exploited by hackers.
2. Attackers are using public exploits to install webshells and take control of devices.
3. Dozens of systems are confirmed compromised; immediate patching is essential.

The Shadowserver Foundation reported on Tuesday that it had identified 77 compromised FortiWeb instances, a slight decrease from 85 the previous day. The organization noted that active exploitation of the vulnerability has been observed since July 11, the same day researchers made exploit code publicly available.

The vulnerability at the heart of these attacks, CVE-2025-25257, is a critical pre-authenticated SQL injection (SQLi) flaw in the FortiWeb graphical user interface.

With a CVSS severity score of 9.6 out of 10, the flaw allows unauthenticated attackers to execute unauthorized code or commands remotely by sending specially crafted HTTP requests.

Fortinet, a major cybersecurity and firewall vendor, uses the FortiWeb appliance as a Web Application Firewall (WAF) to protect web applications and APIs for large enterprises and government agencies.

Fortinet disclosed the vulnerability on July 8, 2025, and released patches to address it. The flaw, discovered by security researcher Kentaro Kawane of GMO Cybersecurity, resides in the FortiWeb Fabric Connector, a component that integrates the WAF with other Fortinet security products.

However, on July 11, cybersecurity firm WatchTowr and one of the flaw’s co-discoverers published PoC exploits, dramatically escalating the risk for organizations running unpatched versions.

The exploits demonstrated how an attacker could leverage SQL injection to plant a webshell or open a reverse shell on a vulnerable device, granting them persistent access and control.

The current wave of attacks confirms cybersecurity experts’ fears that threat actors would quickly weaponize the public exploits. According to Shadowserver, an additional 223 FortiWeb management interfaces remained exposed to the internet as of July 15.

While their patch status is unconfirmed, these systems are considered highly likely to be compromised if they have not been updated. The United States has the highest number of compromised devices at 40, followed by the Netherlands, Singapore, and the United Kingdom.

Fortinet has urged customers to immediately upgrade to secure versions, including FortiWeb 7.6.4, 7.4.8, 7.2.11, or 7.0.11 and later.

For organizations unable to apply the patches right away, the company recommends disabling the HTTP/HTTPS administrative interface as a temporary workaround to block the attack vector.

Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now 

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago