Critical Fortinet Flaw Sparks Wave of Attacks: Web Shells Planted in Unpatched FortiWeb Devices

Listen to this Post

Featured Image

A Surge in Exploits Targets Unpatched Systems Worldwide

A powerful zero-day vulnerability has sent shockwaves through the cybersecurity world. Multiple Fortinet FortiWeb appliances, widely used as Web Application Firewalls (WAFs), have been compromised in a fast-moving wave of attacks. These incidents, linked to a critical remote code execution flaw identified as CVE-2025-25257, highlight how quickly threat actors weaponize public exploits. Despite Fortinet issuing patches earlier in July, attackers began deploying web shells and reverse shells against exposed and unpatched FortiWeb systems just days later, compromising dozens of networks across several countries. The flaw, involving a pre-authentication SQL injection, allows hackers to run arbitrary code on affected devices—posing a serious threat to enterprise security worldwide.

Mass Exploitation Unfolds Within Days of Patch Release

Fortinet FortiWeb devices recently came under coordinated attack through CVE-2025-25257, a critical SQL injection vulnerability disclosed and patched on July 8, 2025. The flaw affects versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, and 7.0.0 through 7.0.10 of FortiWeb. The vulnerability enables remote code execution even before authentication, making it a high-value target for threat actors. Just three days after Fortinet’s patch release, cybersecurity researchers at WatchTowr publicly shared exploit details, including methods for web shell and reverse shell deployment.

By July 14, The Shadowserver Foundation began detecting large-scale exploitation, observing 85 infections on the first day and 77 more on the next. Their analysis revealed attackers exploiting the flaw via SQLi techniques embedded in Authorization headers sent to a vulnerable endpoint: /api/fabric/device/status. This injection allows the placement of a malicious .pth file within Python’s site-packages directory. When FortiWeb’s legitimate CGI script /cgi-bin/ml-draw.py is triggered, it executes the malicious file—granting attackers full remote code access.

Despite warnings, over 220 FortiWeb management interfaces remain publicly exposed, many likely still running outdated versions. Infections have been confirmed across the United States, Netherlands, Singapore, and the United Kingdom. Fortinet has urged users to update to versions 7.6.4, 7.4.8, 7.2.11, or 7.0.11 immediately. For those unable to upgrade right away, it is strongly advised to disable the HTTP/HTTPS admin interface to block access to the vulnerable endpoint.

The urgency is real: FortiWeb is widely used by governments, managed security providers, and large corporations to guard against HTTP-based threats. This incident not only highlights the speed with which vulnerabilities are exploited once made public, but also the critical importance of timely patching.

What Undercode Say:

Why This Attack Is Different

Unlike typical post-authentication exploits, CVE-2025-25257 poses a unique danger because it requires no user credentials to launch. Attackers can remotely trigger the flaw without any prior access, escalating the risk considerably. The SQLi vulnerability sits in a publicly accessible API endpoint, offering an easy path to full remote command execution.

The Exploitation Chain Is Ingenious

The use of a Python .pth file to inject malicious code demonstrates an advanced exploitation chain. By manipulating the Authorization header, attackers evade many standard detection methods. The execution path through a legitimate CGI script adds another layer of stealth, allowing the payload to be activated only upon specific requests.

Public Exploits Triggered Mass Infections

WatchTowr’s public release of exploit scripts, although intended for research and defensive purposes, unintentionally became a roadmap for hackers. Within 72 hours of its publication, real-world exploitation began. This reinforces how fast the black hat community can mobilize once proof-of-concept code becomes available.

Fortinet’s Patch Window Was Too Short

Despite Fortinet’s relatively fast response, the timeline between patch release and public exploit disclosure was too narrow for many organizations to react. Enterprises often require weeks to schedule downtime, test patches, and deploy updates across large infrastructures. This lag time created a perfect window for attackers.

Cloud Security Lags Behind Threat Actor Agility

This case echoes a broader problem in 2025: threat actors have evolved rapidly, while many cloud-first businesses still lack proper patch automation and exposure management. FortiWeb’s global footprint and its WAF role in filtering HTTP traffic make it a valuable target for anyone seeking to bypass perimeter defenses.

Attackers Go After Low-Hanging Fruit

While cloud attacks are becoming more sophisticated, this campaign proves that attackers continue to rely on basic vulnerabilities—like SQL injection—to gain initial access. The successful compromise of 85+ FortiWeb systems wasn’t achieved with novel exploits, but with well-understood techniques weaponized swiftly.

Countries With Highest Infection Rates at Risk

The fact that 40 infections occurred in the U.S. alone reveals how widespread vulnerable deployments remain even in mature security environments. The Netherlands, Singapore, and the UK are also significantly impacted, pointing to the global scale of the issue.

Poor Visibility Into Firmware Versions

One key challenge facing analysts is that many exposed FortiWeb interfaces don’t publicly reveal their firmware version, making it hard to determine how many are truly vulnerable. This adds complexity to response efforts and may delay cleanup for affected organizations.

Risk Mitigation Steps Are Clear

Administrators must act now. If patching cannot be done immediately, disabling the web admin interface is a mandatory interim measure. Access control, strict firewall rules, and endpoint monitoring should also be enforced to detect signs of compromise.

🔍 Fact Checker Results:

✅ CVE-2025-25257 is a verified SQL injection flaw affecting FortiWeb devices
✅ Exploits were made public on July 11, 2025, by WatchTowr and faulty \ptrrr
❌ Over 220 exposed FortiWeb instances remain unpatched as of July 15, 2025

📊 Prediction:

🚨 Expect a significant spike in exploitation over the next two weeks, especially targeting unmanaged FortiWeb interfaces in enterprise environments. As ransomware groups and APTs pick up on the availability of reliable exploits, more advanced payloads—including credential stealers and persistence mechanisms—are likely to be deployed. By August 2025, we may see at least one major breach traced back to this vulnerability.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.github.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin