Impact
An improper neutralization of CRLF sequences in HTTP headers allows an attacker intercepting or forging captive portal authentication requests to inject arbitrary headers. This HTTP response splitting can alter the structure of the server’s response, potentially leading to session hijacking, redirection to malicious sites, or the execution of unintended actions by the client’s browser. The weakness is identified as CWE-113 – HTTP Response Splitting.
Affected Systems
Affected Fortinet products include FortiOS (all 7.2, 7.4, and 7.6.0 through 7.6.4 releases) and FortiProxy (all 7.2, 7.4, and 7.6.0 through 7.6.4). Users of these products should verify current build numbers against the provided ranges.
Risk and Exploitability
Based on the description, it is inferred that attackers would need to observe or inject HTTP requests to a captive portal, a scenario that could be realistic in open or unmonitored networks. The CVSS score is 3.1, indicating low base severity, and the EPSS score is below 1%, suggesting a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Given the low scores and the need for a specific network scenario, the overall risk is considered low.
OpenCVE Enrichment