Impact
This vulnerability arises from improper neutralization of CRLF sequences in HTTP headers, allowing an attacker who holds a valid web filter override token to craft a malicious link that, when clicked by a target user, injects arbitrary headers into the HTTP response. The injected headers can be used for session hijacking, cookie theft, or other information disclosure, although the CVSS score of 3.4 indicates the overall impact is limited. The weakness is classified as CWE‑113.
Affected Systems
Affected products are Fortinet FortiOS versions 7.6.0 through 7.6.4, all 7.4 releases, and all 7.2 releases; Fortinet FortiProxy versions 7.6.0 through 7.6.4, all 7.4 releases, and all 7.2 releases. FortiSASE customers remain safe once running version 25.4.b or newer.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. Exploitation is remote and requires an attacker to possess a valid web filter override token and persuade a user to click a crafted link, after which the attacker can inject custom headers into the response sent to that client. Overall, the risk is low but not negligible, and the threat is best mitigated by applying the vendor‑provided updates.
OpenCVE Enrichment