# CVE-2025-64446

> A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

- **CVSS:** 9.4 (CRITICAL)
- **EPSS:** 89.5%
- **CISA KEV:** yes
- **CWE:** CWE-23

Canonical: https://intel.threadlinqs.com/cve/CVE-2025-64446
Full threat coverage + IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
