CVE-2025-47890 LOW

CVE-2025-47890

Vendor Fortinet
Product FortiSASE
Weakness CWE-601 · Open redirect
Published October 14, 2025
Last update June 9, 2026

CVSS base score

2.5/10
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C

What the vulnerability does

01Description

An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker to perform an open redirect attack via crafted HTTP requests.

Key dates

02Disclosure timeline

October 14, 2025 CVE published
June 9, 2026 Record updated