URL Redirection Vulnerability in Fortinet's FortiOS and FortiProxy
CVE-2025-47890

2.5LOW

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
14 October 2025

What is CVE-2025-47890?

The vulnerability found in Fortinet's FortiOS and FortiProxy products allows attackers to exploit an open redirect mechanism through carefully crafted HTTP requests. This flaw could enable unauthenticated individuals to redirect users to malicious sites, potentially leading to further attacks or unauthorized data access. It is critical for organizations using affected versions to assess their exposure and implement necessary mitigations to safeguard sensitive information.

Affected Version(s)

FortiOS 7.6.0 <= 7.6.2

FortiOS 7.4.0 <= 7.4.8

FortiOS 7.2.0 <= 7.2.12

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47890 : URL Redirection Vulnerability in Fortinet's FortiOS and FortiProxy