---
id: CVE-2025-64471
title: >-
  A use of password hash instead of password for authentication vulnerability
  [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb
  7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through
  7.2.11, For…
summary: >-
  A use of password hash instead of password for authentication vulnerability
  [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb
  7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through
  7.2.11, For…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-836
vendor: fortinet
product: fortiweb
affected:
  - 'fortiweb >= 7.0.0, <= 7.0.11'
  - 'fortiweb >= 7.2.0, <= 7.2.11'
  - 'fortiweb >= 7.4.0, <= 7.4.10'
  - 'fortiweb >= 7.6.0, <= 7.6.4'
  - 'fortiweb >= 8.0.0, <= 8.0.1'
published: '2025-12-09'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64471'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-25-984'
    label: psirt@fortinet.com
tags:
  - nvd
epss: 0.00336
epssPercentile: 0.24334
ingestedAt: '2026-09-25T23:21:16.904Z'
---

## Overview

A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to use the hash in place of the password to authenticate via crafted HTTP/HTTPS requests

## Affected

- `fortiweb >= 7.0.0, <= 7.0.11`
- `fortiweb >= 7.2.0, <= 7.2.11`
- `fortiweb >= 7.4.0, <= 7.4.10`
- `fortiweb >= 7.6.0, <= 7.6.4`
- `fortiweb >= 8.0.0, <= 8.0.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
