Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Low

SSRF in Fortinet FortiSandbox GUI

IdentifiersCVE-2025-67685CWE-918· Server-Side Request Forgery (SSRF)

CVE-2025-67685 is a server-side request forgery (SSRF) vulnerability in the Fortinet FortiSandbox GUI component affecting FortiSandbox 5.0.0 through 5.0.4, and all versions in the 4.4, 4.2, and 4.0 branches. The flaw allows an authenticated attacker to submit crafted HTTP requests that cause the appliance to proxy requests to localhost or other internal IP addresses. Based on the available reporting, the SSRF is constrained to plaintext/non-TLS endpoints only. Fortinet and supporting reporting associate the issue with CWE-918; some reporting also attributes the root cause to inadequate input validation and improper access control in the GUI.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an authenticated attacker to use the FortiSandbox appliance as a proxy to reach internal plaintext-only services that may not otherwise be directly accessible. This can expose internal service metadata, support limited internal network reconnaissance, and potentially facilitate follow-on pivoting in segmented or misconfigured environments. Available reporting indicates the issue is low severity and does not provide direct code execution by itself; impact is primarily limited confidentiality and integrity exposure against reachable internal plaintext endpoints, with no stated direct availability impact.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, restrict and closely monitor access to the FortiSandbox GUI, especially high-privilege administrative access required for exploitation. Audit GUI logs for anomalous internal fetches or requests targeting localhost and internal IP ranges. Reduce the reachable attack surface by limiting the appliance's network access to sensitive internal plaintext services where operationally feasible, and enforce segmentation controls to prevent the appliance from reaching unnecessary internal endpoints.

Remediation

Patch, then assume compromise.

Upgrade affected FortiSandbox installations to a fixed release. Specifically, FortiSandbox 5.0.0 through 5.0.4 should be upgraded to 5.0.5 or later. For FortiSandbox 4.4, 4.2, and 4.0, all versions are affected; administrators should migrate those systems to a supported fixed release as advised by Fortinet via the FortiGuard portal and official upgrade guidance.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
FortinetFortisandboxapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity4

Community discussion across Reddit, Mastodon, and other social sources.