---
id: CVE-2025-64447
title: >-
  A reliance on cookies without validation and integrity checking vulnerability
  in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5,
  FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0
  through 7.…
summary: >-
  A reliance on cookies without validation and integrity checking vulnerability
  in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5,
  FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0
  through 7.…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-565
vendor: fortinet
product: fortiweb
affected:
  - 'fortiweb >= 7.0.0, <= 7.0.11'
  - 'fortiweb >= 7.2.0, <= 7.2.11'
  - 'fortiweb >= 7.4.0, <= 7.4.10'
  - 'fortiweb >= 7.6.0, <= 7.6.5'
  - 'fortiweb >= 8.0.0, <= 8.0.1'
published: '2025-12-09'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64447'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-25-945'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.08352
epssPercentile: 0.94763
ingestedAt: '2026-09-25T23:21:16.904Z'
---

## Overview

A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS request via forged cookies, requiring prior knowledge of the FortiWeb serial number.

## Affected

- `fortiweb >= 7.0.0, <= 7.0.11`
- `fortiweb >= 7.2.0, <= 7.2.11`
- `fortiweb >= 7.4.0, <= 7.4.10`
- `fortiweb >= 7.6.0, <= 7.6.5`
- `fortiweb >= 8.0.0, <= 8.0.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
