VDB

CVE-2025-48840

CVE-2025-48840 PUBLISHED CVSS 5 MEDIUM

An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a specially crafted request.

EPSS 0.09% · 26.0th percentile

Risk Scores

CVSS 3.1
5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:U/RC:C
EPSS Score
0.09%
26.0th percentile

Affected Products

VendorProductVersions
FortinetFortiWeb7.0.0, 7.4.0, 7.6.0
fortinetfortiweb7.0.0, 7.6.0, 7.0.0

Timeline

  • Mar 10, 2026 CVE Published
  • Mar 11, 2026 EPSS Score
  • Mar 12, 2026 EPSS Score
  • Mar 12, 2026 CVE Updated
  • Mar 13, 2026 EPSS Score
  • Mar 14, 2026 EPSS Score
  • Mar 15, 2026 EPSS Score
  • Mar 16, 2026 EPSS Score
  • Mar 17, 2026 EPSS Score
  • Mar 17, 2026 Security Advisory
  • Mar 17, 2026 Security Advisory
  • Mar 17, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›