Junglewise Threat Intelligence

CVE-2025-55018: Fortinet FortiOS HTTP request smuggling in firewall policies

CVE-2025-55018 · Severity: medium · CVSS 5.8 · Published 2026-02-10

Technologies: Siemens Ruggedcom Ape1808, Fortinet FortiOS. Vendors: Siemens, Fortinet.

Executive brief

A vulnerability in Fortinet's firewall operating system could allow an unauthorized person to bypass security policies. By sending specially crafted web traffic, an attacker can 'smuggle' hidden requests that the firewall fails to log or inspect properly. This could allow malicious commands to reach internal web servers that were intended to be protected.

Technical details

An inconsistent interpretation of HTTP requests (HTTP Request Smuggling, CWE-444) exists in FortiOS. The vulnerability is triggered when the firewall processes specially crafted HTTP headers, leading to a discrepancy in how the firewall and the backend server define request boundaries. This issue specifically affects configurations using Virtual IPs (VIP) to forward traffic to HTTP/1.1 servers. An unauthenticated remote attacker can exploit this to smuggle requests past firewall security policies, potentially leading to unauthorized command execution on backend systems or bypassing access controls. Patches are available in FortiOS versions 7.6.1, 7.4.10, and subsequent releases.

Affected products

  • Fortinet FortiOS 7.6.0, 7.4.0 through 7.4.9, 7.2 all versions, 7.0 all versions, 6.4.3 through 6.4.16
  • Siemens RUGGEDCOM APE1808 All versions with Fortinet NGFW < V7.4.10

Timeline

  • 2026-02-10: disclosed: Initial publication by Fortinet
  • 2026-02-10: advisory: Fortinet advisory FG-IR-25-667 published
  • 2026-02-26: other: Impact details updated by vendor
  • 2026-03-10: advisory: Siemens published advisory SSA-975644 for RUGGEDCOM devices

References

Related threats