Junglewise Threat Intelligence

CVE-2025-62675: Fortinet FortiOS and FortiProxy HTTP response splitting in Web Filter

CVE-2025-62675 · Severity: low · CVSS 3.4 · Published 2026-07-14

Technologies: Fortinet FortiOS, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

Fortinet FortiOS and FortiProxy, which are used to manage and secure corporate network traffic, contain a security flaw in their web filtering component. An attacker could trick a user into clicking a malicious link to inject unauthorized information into the user's web session. While this requires the attacker to possess a specific security token and involves user interaction, it could be used to bypass certain security controls or mislead users.

Technical details

An HTTP Response Splitting vulnerability (CWE-113) exists in the Web Filter warning page of Fortinet FortiOS and FortiProxy. The flaw is caused by improper neutralization of CRLF sequences in HTTP headers. An attacker who possesses a valid web filter override token can exploit this by tricking a user into clicking a specially crafted link, leading to the injection of arbitrary headers. This is categorized as a low-severity issue due to the requirement for a valid token and user interaction (UI:R). Patches are available in FortiOS/FortiProxy versions 7.6.5 and above; users on 7.4 and 7.2 branches are advised to migrate to a fixed release.

Affected products

  • Fortinet FortiOS 7.6.0 through 7.6.4, 7.4 all versions, 7.2 all versions
  • Fortinet FortiProxy 7.6.0 through 7.6.4, 7.4 all versions, 7.2 all versions

Timeline

  • 2026-07-14: advisory: Initial publication by Fortinet
  • 2026-07-14: disclosed

References

Related threats