Junglewise Threat Intelligence

CVE-2025-53679: Fortinet FortiSandbox OS command injection in GUI backup options

CVE-2025-53679 · Severity: high · CVSS 7.2 · Published 2025-12-09

Technologies: Fortinet FortiSandbox, Fortinet Fortisandbox Cloud. Vendors: Fortinet.

Executive brief

FortiSandbox is a security appliance used to identify and isolate advanced threats by executing suspicious files in a safe environment. A vulnerability in its management interface allows an administrator with high-level privileges to execute unauthorized commands on the underlying system. This could lead to a complete takeover of the appliance, potentially compromising the integrity of the threat analysis process.

Technical details

An OS command injection vulnerability (CWE-78) exists in the FortiSandbox GUI, specifically within the backup options component. The flaw stems from improper neutralization of special elements in user-supplied input before it is passed to a system shell. A remote attacker with high privileges (PR:H) can exploit this by sending specially crafted HTTP or HTTPS requests to the management interface. Successful exploitation allows for arbitrary code execution with the privileges of the web server or underlying system. Fortinet has released patches in versions 5.0.3 and 4.4.8 to address this issue.

Affected products

  • Fortinet FortiSandbox 5.0.0 through 5.0.2, 4.4.0 through 4.4.7, 4.2 all versions, 4.0 all versions
  • Fortinet FortiSandbox Cloud 24.1, 23 all versions

Timeline

  • 2025-12-09: disclosed: Initial publication by Fortinet
  • 2025-12-09: advisory

References

Related threats