PT-2026-58056 · Fortinet · Fortios+1

CVE-2025-62826

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions FortiOS versions 7.6.0 through 7.6.4 FortiOS versions 7.4.x FortiOS versions 7.2.x FortiProxy versions 7.6.0 through 7.6.4 FortiProxy versions 7.4.x FortiProxy versions 7.2.x
Description An improper neutralization of CRLF (Carriage Return Line Feed) sequences in HTTP headers, also known as HTTP Response Splitting, allows a remote attacker to inject arbitrary headers via crafted HTTP requests. This issue can be exploited by an attacker capable of intercepting and modifying a user's captive portal authentication request to gain unauthorized access to modify authentication requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09915
CVE-2025-62826

Affected Products

Fortios
Fortiproxy