CVE-2025-67685 | Fortinet FortiSandbox up to 4.0.6/4.2.8/4.4.8/5.0.4 HTTP server-side request forgery (FG-IR-25-783 / EUVD-2026-2215)
A vulnerability marked as critical has been reported in Fortinet FortiSandbox up to 4.0.6/4.2.8/4.4.8/5.0.4. Affected by this issue is some unknown functionality of the component HTTP Handler. The manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2025-67685. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.