Junglewise Threat Intelligence

CVE-2025-31366: Fortinet FortiOS and FortiProxy XSS and Open Redirect in Web Filter

CVE-2025-31366 · Severity: medium · CVSS 4.7 · Published 2025-10-14

Technologies: Siemens Ruggedcom Ape1808, Fortinet FortiOS, Fortinet Fortisase, Fortinet FortiProxy. Vendors: Siemens, Fortinet.

Executive brief

A security vulnerability exists in the web filtering warning pages of Fortinet networking devices, including FortiOS firewalls and FortiProxy gateways. An attacker could use this flaw to redirect users to malicious websites or execute unauthorized scripts in a user's browser by tricking them into clicking a specially crafted link. This could lead to the theft of login credentials or sensitive session information from users managing or accessing the network.

Technical details

The vulnerability consists of Improper Neutralization of Input During Web Page Generation (CWE-79) and URL Redirection to Untrusted Site (CWE-601) within the Web Filter warning page component. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request that, if processed by a victim's browser (typically via a malicious link), executes arbitrary JavaScript in the context of the victim's session or redirects them to an external malicious domain. The attack requires user interaction (clicking a link). Fortinet has released patches for FortiOS (7.6.4, 7.4.9) and FortiProxy (7.6.4), while FortiSASE was remediated in version 25.3.b.

Affected products

  • Fortinet FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions, 6.4 all versions
  • Fortinet FortiProxy 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions
  • Fortinet FortiSASE 25.2.a
  • Siemens RUGGEDCOM APE1808 All versions with Fortinet NGFW < V7.4.9

Timeline

  • 2025-10-14: disclosed: Initial publication by Fortinet
  • 2025-10-14: advisory
  • 2025-05-13: other: Siemens advisory publication (pre-dated Fortinet's specific CVE disclosure)

References

Related threats