3.4
/ 10
LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C
Description
A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to proxy internal requests limited to plaintext endpoints only via crafted HTTP requests.
Basic Information
ID
CVE-2025-67685
Source
fortinet
Published
Jan 13, 2026 at 16:32
Affected Product
Vendor
Fortinet
Product
FortiSandbox
Version
5.0.0
Affected Versions
Fortinet FortiSandbox 5.0.0
Fortinet FortiSandbox 4.4.0
Fortinet FortiSandbox 4.2.1
Fortinet FortiSandbox 4.0.0
Fortinet FortiSandbox 4.4.0
Fortinet FortiSandbox 4.2.1
Fortinet FortiSandbox 4.0.0