PT-2026-58055 · Fortinet · Fortios+1

CVE-2025-62675

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FortiOS versions 7.6.0 through 7.6.4 FortiOS versions 7.4.x FortiOS versions 7.2.x FortiProxy versions 7.6.0 through 7.6.4 FortiProxy versions 7.4.x FortiProxy versions 7.2.x
Description An improper neutralization of CRLF (Carriage Return Line Feed) sequences in HTTP headers, also known as HTTP Response Splitting, allows a remote attacker with a valid web filter override token to inject arbitrary headers by tricking a user into clicking a crafted link. This issue may lead to the execution of arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09920
CVE-2025-62675

Affected Products

Fortios
Fortiproxy