An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker to perform an open redirect attack via crafted HTTP requests.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-542 | Vendor Advisory |
| https://cert-portal.siemens.com/productcert/html/ssa-864900.html |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
09 Jun 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
14 Jan 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker to perform an open redirect attack via crafted HTTP requests. |
22 Oct 2025, 16:48
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-24-542 - Vendor Advisory | |
| First Time |
Fortinet fortisase
Fortinet Fortinet fortios Fortinet fortiproxy |
|
| CPE | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisase:25.3.40:*:*:*:mature:*:*:* cpe:2.3:a:fortinet:fortisase:25.3.40:*:*:*:feature:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
14 Oct 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-14 16:15
Updated : 2026-06-17 09:28
NVD link : CVE-2025-47890
Mitre link : CVE-2025-47890
CVE.ORG link : CVE-2025-47890
JSON object : View
Products Affected
fortinet
- fortios
- fortiproxy
- fortisase
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
