CVE-2025-53679

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSandbox version 5.0.0 through 5.0.2 and before 4.4.7 GUI allows a remote privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
6.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:X/RL:O/RC:C
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
VendorProductVersion
fortinet_fortisandbox_paas
23.1
fortinet_fortisandbox_paas
23.3
fortinet_fortisandbox_paas
23.4
fortinet_fortisandbox_paas
24.1
fortinetfortisandbox
𝑥
≤ 4.4.7
fortinetfortisandbox
5.0.0 ≤
𝑥
≤ 5.0.2
𝑥
= Vulnerable software versions