CVE-2025-64471

A

use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to use the hash in place of the password to authenticate via crafted HTTP/HTTPS requests

References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*

History

10 Dec 2025, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 18:16

Updated : 2025-12-10 19:16


NVD link : CVE-2025-64471

Mitre link : CVE-2025-64471

CVE.ORG link : CVE-2025-64471


JSON object : View

Products Affected
CWE
CWE-836

Use of Password Hash Instead of Password for Authentication