Possible FortiWeb Path-Traversal Authentication Bypass Exploitation CVE-2025-64446

PremiumReviewedSigma · High · v1
Category
webserver
Author
HuntRule
Published
2026-09-25
Updated
2026-09-25

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule detects inbound POST requests containing a path-traversal sequence that reaches the FortiWeb fwbcgi CGI endpoint through the cmdb admin API, matching the authentication-bypass exploitation of CVE-2025-64446 observed in the wild. Successful exploitation lets an unauthenticated attacker create administrative accounts and run privileged commands on the appliance.

Related detections9 linkedT1190 — drag to rearrange
Possible Ivanti EPMM In-Memory Java Webshell Access via mifs 403.jsp
Suspicious BeyondTrust Remote Support Probing of nw Endpoint via Webserver
Suspicious SonicWall SSL-VPN Reconnaissance Endpoints via Webserver
Suspicious Access to Spring Boot Actuator Heapdump Endpoint
Possible Out-of-Band OAST Callback Domain Resolution via DNS
Suspicious Executable Run from IIS aspnet_client or Windows Tasks Directory via process_creation
Suspicious Telerik UI RadAsyncUpload Request Indicating CVE-2019-18935 Exploitation (via webserver)
Malicious IIS Worker Process Spawning Shell for Out-of-Band Interaction via Command Line
Malicious wp2shell WordPress Exploitation via Batch Endpoint User Agent
Possible FortiWeb Path-Traversal Authentication Bypass Exploitation CVE-2025-64446
Pivot detection · T1190 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.