CVE-2025-67685

A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0

Severity
Low 3.4
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.004
34.3th percentile
Discovered by
Third party
Vendor advisory field
Published
Jan 13, 2026
Assigned by fortinet

Description

A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to proxy internal requests limited to plaintext endpoints only via crafted HTTP requests.

Weakness: CWE-918

Affected products

Vendor Product Category Matched by
Fortinet FortiSandbox Threat Detection & Sandbox cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiSandbox

Credit

Fortinet is pleased to thank Jason McFadyen of Trend Research working with Trend Micro Zero Day Initiative for reporting this vulnerability under responsible disclosure.

Vendor remediation

Upgrade to FortiSandbox version 5.0.5 or above

Something wrong here?