PT-2025-50114 · Fortinet · Fortisandbox
Published
2025-12-09
·
Updated
2025-12-16
·
CVE-2025-53949
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiSandbox versions 4.0 all versions
Fortinet FortiSandbox versions 4.2 all versions
Fortinet FortiSandbox versions 4.4.0 through 4.4.7
Fortinet FortiSandbox versions 5.0.0 through 5.0.2
Description
The Fortinet FortiSandbox software contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') issue. This allows an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests. The issue affects multiple areas, including the
upload vdi file functionality, the name parameter, and the admindel confirm parameter. The vulnerability is triggered by crafted HTTP requests. The name parameter and upload vdi file are specifically identified as points of exploitation.Recommendations
Fortinet FortiSandbox version 4.0 all versions: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Fortinet FortiSandbox version 4.2 all versions: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Fortinet FortiSandbox versions 4.4.0 through 4.4.7: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Fortinet FortiSandbox versions 5.0.0 through 5.0.2: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortisandbox