CVE-2025-52970, also known as FortMajeure, is an improper parameter handling vulnerability in the FortiWeb GUI. A malformed or unexpected cookie parameter can cause incorrect session-cryptographic processing, reportedly resulting in use of an all-zero secret for session encryption and HMAC signing. An unauthenticated remote attacker possessing non-public information relating to the target FortiWeb device and user can submit a specially crafted request, forge a valid session, and authenticate as an existing user, including an administrator. Affected releases are FortiWeb 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, and 7.0.0 through 7.0.10. FortiWeb 8.0 is not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a weaponized exploit for CVE-2025-52970, targeting Fortinet FortiWeb appliances. The exploit leverages an authentication bypass and SQL injection vulnerability in the '/api/fabric/device/status' endpoint to upload a webshell to '/migadmin/cgi-bin/x.cgi'. The exploit script (CVE-2025-52970.py) is written in Python and automates the process of exploiting the SQL injection to write and activate the webshell, then provides an interactive shell interface to execute arbitrary commands on the target system via the webshell. The exploit also uses a secondary file ('/var/log/lib/python3.10/pylab.py') as part of a 'chmod' gadget to ensure the webshell is executable. The README provides usage instructions and references. The main entry point is the Python script, which requires the target URL as input. The exploit is operational and provides full remote code execution capabilities if the target is vulnerable.
This repository contains a single Python exploit script (Forti_Bang.py) targeting Fortinet FortiWeb appliances vulnerable to CVE-2025-52970. The exploit leverages an authentication bypass and SQL injection vulnerability in the '/api/fabric/device/status' API endpoint. The script automates the process of creating a temporary SQL table, writing a shell script webshell in chunks, exporting it to '/migadmin/cgi-bin/x.cgi', and uploading a helper Python script to set executable permissions. Once the webshell is in place, the attacker can execute arbitrary commands by sending HTTP requests to '/cgi-bin/x.cgi' with the desired command in the User-Agent header. The repository also includes a README.md with detailed usage instructions and a LICENSE file. The exploit is operational, providing a working webshell and command execution capability, and is intended for research and educational purposes only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An improper parameter handling vulnerability in Fortinet FortiWeb (multiple versions) allows unauthenticated remote attackers with certain non-public information to gain admin privileges via a crafted request.
A critical authentication bypass vulnerability in Fortinet FortiWeb devices that can allow unauthenticated attackers to gain administrative access to the web application firewall.
An authentication bypass vulnerability in Fortinet FortiWeb (CVE-2025-52970) allows unauthenticated attackers to access admin-only API endpoints, resulting in broken access control. The flaw can be detected by sending unauthenticated requests to /api/v2.0/system/status.systemstatus and matching on admin-only JSON keys in the response.
A broken access control vulnerability in Fortinet FortiWeb (CVE-2025-52970) allows authentication bypass, potentially enabling attackers to access protected resources without valid credentials.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.