Database/Control plane, storage & DevOps
Fortinet FortiWeb: Unauthenticated SQL injection
CVSS 9.8CVE-2025-25257Control plane, storage & DevOpsKnown exploitedcurated
Impact
Unauthenticated SQL injection -> pre-auth code execution on the WAF
Who can reach it
Network (remote)
What to do
Control-plane: firmware upgrade
References
Related entries
- GitLab (ruby-saml): ReXML/Nokogiri parser differentialCVE-2025-25291 · GitLab (ruby-saml)Critical
- HPE StoreOnce: unauthenticated command injection allows remote code execution on the backup applianceCVE-2025-37089 · HPE StoreOnce (command injection RCE)Critical
- HPE StoreOnce (server-side request forgery): SSRF from the backup appliance, letting an unauthenticated attacker pivotCVE-2025-37090 · HPE StoreOnce (server-side request forgery)Critical
- HPE StoreOnce (authentication bypass): Unauthenticated attacker bypasses authentication on StoreOnce entirely, gainingCVE-2025-37093 · HPE StoreOnce (authentication bypass)Critical
- HPE StoreOnce (directory traversal information disclosure): Unauthenticated directory traversal disclosing filesCVE-2025-37095 · HPE StoreOnce (directory traversal information disclosure)Critical
- HPE Insight Remote Support (remote code execution): Unauthenticated remote code execution on the Insight RS serverCVE-2025-37099 · HPE Insight Remote Support (remote code execution)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.