Back

HIGH

Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests

Published Mar 11, 2025

Description

Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests.

Affected products

Remediation

Vendor solution

Upgrade to FortiSandbox version 5.0.0 or above Upgrade to FortiSandbox version 4.4.6 or above

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fortinet
Published Mar 11, 2025
Updated Feb 26, 2026
Reserved Nov 27, 2024
CISA Vulnrichment
Updated Mar 12, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a