CVE-2025-64471 - Fortinet FortiWeb Password Hash Authentication Bypass

CVE-2025-64471 - Fortinet FortiWeb Password Hash Authentication Bypass

CVE ID : CVE-2025-64471 Published : Dec. 9, 2025, 6:16 p.m. | 15 minutes ago Description : A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to use the hash in place of the password to authenticate via crafted HTTP/HTTPS requests Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 9, 2025
Affected Product: Fortinet
CWE: CWE-836

Source: Telegram CVE Monitor