Drooid Logo
Back to story perspectives

Full Breakdown

Fortinet's Silent Patch Raises Alarms Over Critical Vulnerabilities

11/19/2025, 7:55:29 AM

Overview of the Vulnerabilities

Security researchers have raised concerns regarding two critical vulnerabilities in Fortinet’s FortiWeb web application firewall, tracked as CVE-2025-64446. These flaws, which include a relative path traversal vulnerability and an authentication bypass issue, have been actively exploited in the wild. The path traversal vulnerability, rated 9.8 on the CVSS scale, allows unauthenticated actors to access internal CGI endpoints and execute administrative commands, potentially leading to a complete takeover of affected devices.

Timeline of Events

  • October 6, 2023: The vulnerability is first detected by researchers at DefusedCyber.
  • October 28, 2023: Fortinet releases a silent patch in version 8.0.2 of FortiWeb but does not disclose the vulnerability.
  • November 14, 2023: Fortinet publicly acknowledges the vulnerability and its exploitation, coinciding with the addition of CVE-2025-64446 to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog.

Criticism of Fortinet's Response

Researchers and federal authorities have criticized Fortinet for its delayed disclosure and lack of urgency in addressing the vulnerabilities. The company reportedly patched the flaws without assigning a CVE or informing customers until weeks later, leaving many users unaware of the critical risks. Ben Harris, CEO of watchTowr, emphasized that the lack of communication likely led many customers to neglect applying the necessary patches, resulting in potential compromises.

Ryan Emmons, a security researcher at Rapid7, noted that the delayed public advisory hindered the ability of defenders to respond effectively, giving attackers a significant advantage. The absence of timely information has been described as creating an "information vacuum," complicating the response efforts of security teams already overwhelmed with other vulnerabilities.

Official Statements & Responses

Fortinet defended its actions, stating that its product security incident response team began addressing the vulnerabilities as soon as they were identified. A spokesperson remarked, “Fortinet diligently balances our commitment to the security of our customers and our culture of responsible transparency.” They also indicated that affected customers were being directly informed about necessary actions.

Broader Implications

The incident highlights the risks associated with silent patching practices, which can leave organizations vulnerable. Caitlin Condon from VulnCheck criticized this approach, stating that it invites attackers while withholding crucial information from defenders. The exploitation of CVE-2025-64446 underscores the need for improved communication and transparency from technology vendors regarding security vulnerabilities.

What's Next

Fortinet has recommended that customers disable HTTP or HTTPS for internet-facing interfaces until they can upgrade to the latest version. Additionally, organizations are advised to review their configurations and logs for unauthorized changes or accounts. As the cybersecurity community continues to monitor the situation, further investigations into the extent of the exploitation and the identification of affected organizations are anticipated.

Verbatim Quotes

  • “Attacks have been widespread and indiscriminate according to shared evidence since at least early October — long before the industry was able to pull the fire alarm, and arguably exacerbated by the silence from Fortinet,” — Ben Harris, CEO of watchTowr
  • “When a vendor has knowledge of product flaws and a patch is published, it’s imperative that defenders are given a heads-up notice with as much actionable information as possible.” — Ryan Emmons, Security Researcher at Rapid7
  • “Silently patching vulnerabilities is an established bad practice that enables attackers and harms defenders, particularly for devices and systems (including FortiWeb) that have previously been exploited in the wild,” — Caitlin Condon, VulnCheck