CVE-2025-62675: Header injection in Web Filter warning page
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link.
Other sources
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.5 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 8.0.0 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.5
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62675?
The severity of CVE-2025-62675 is medium with a score of 4.3.
What systems are affected by CVE-2025-62675?
CVE-2025-62675 affects Fortinet FortiOS and FortiProxy.
How do I fix CVE-2025-62675?
To fix CVE-2025-62675, ensure that all software instances of FortiOS and FortiProxy are updated to the latest version provided by Fortinet.
What type of vulnerability is CVE-2025-62675?
CVE-2025-62675 is an HTTP Response Splitting vulnerability due to improper neutralization of CRLF sequences in HTTP headers.
Can CVE-2025-62675 lead to arbitrary header injection?
Yes, CVE-2025-62675 allows an attacker to inject arbitrary headers if they possess a valid web filter override token.