CVE-2025-62826
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiO
Description
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept and modify a user's captive portal authentication request to inject arbitrary headers via crafted HTTP requests.
Weakness: CWE-113
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
| Fortinet | FortiPAM | Identity / IAM / MFA | cna-assigner |
| Fortinet | FortiProxy | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (3)
- Fortinet · FortiPAM
- Fortinet · FortiProxy
- Fortinet · FortiOS
Vendor remediation
Upgrade to FortiProxy version 7.6.5 or above Upgrade to upcoming FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.5 or above Fortinet remediated this issue in FortiSASE version 25.4.b and hence customers do not need to perform any action. Fortinet remediated this issue in FortiSASE version 25.4.a and hence customers do not need to perform any action.