CVE-2025-47890

An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker to perform an open redirect attack via crafted HTTP requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:fortinet:fortisase:25.3.40:*:*:*:feature:*:*:*
cpe:2.3:a:fortinet:fortisase:25.3.40:*:*:*:mature:*:*:*

History

09 Jun 2026, 10:16

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-864900.html -

14 Jan 2026, 10:16

Type Values Removed Values Added
Summary (en) An URL Redirection to Untrusted Site vulnerabilities [CWE-601] in FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiProxy 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions; FortiSASE 25.2.a may allow an unauthenticated attacker to perform an open redirect attack via crafted HTTP requests. (en) An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker to perform an open redirect attack via crafted HTTP requests.

22 Oct 2025, 16:48

Type Values Removed Values Added
References () https://fortiguard.fortinet.com/psirt/FG-IR-24-542 - () https://fortiguard.fortinet.com/psirt/FG-IR-24-542 - Vendor Advisory
First Time Fortinet fortisase
Fortinet
Fortinet fortios
Fortinet fortiproxy
CPE cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisase:25.3.40:*:*:*:mature:*:*:*
cpe:2.3:a:fortinet:fortisase:25.3.40:*:*:*:feature:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

14 Oct 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 16:15

Updated : 2026-06-17 09:28


NVD link : CVE-2025-47890

Mitre link : CVE-2025-47890

CVE.ORG link : CVE-2025-47890


JSON object : View

Products Affected

fortinet

  • fortios
  • fortiproxy
  • fortisase
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')