CVE-2025-67685

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
13/01/2026
Last modified:
14/01/2026

Description

A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to proxy internal requests limited to plaintext endpoints only via crafted HTTP requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:* 4.0.0 (including) 5.0.5 (excluding)


References to Advisories, Solutions, and Tools