CVE-2025-48840

An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a specially crafted request.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-10 18:17

Updated : 2026-03-12 21:20


NVD link : CVE-2025-48840

Mitre link : CVE-2025-48840

CVE.ORG link : CVE-2025-48840


JSON object : View

Products Affected

fortinet

  • fortiweb
CWE
CWE-290

Authentication Bypass by Spoofing