An URL Redirection to Untrusted Site vulnerabilities [CWE-601] in FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiProxy 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions; FortiSASE 25.2.a may allow an unauthenticated attacker to perform an open redirect attack via crafted HTTP requests.
2025-10-14T16:15:38.667
2025-10-22T16:48:09.920
Analyzed
CVSSv3.1: 2.6 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | fortinet | fortios | < 7.4.9 | Yes |
| Operating System | fortinet | fortios | < 7.6.4 | Yes |
| Application | fortinet | fortiproxy | < 7.6.4 | Yes |
| Application | fortinet | fortisase | 25.3.40 | Yes |
| Application | fortinet | fortisase | 25.3.40 | Yes |