CVE-2025-53679: OS command injection in GUI backup options
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSandbox GUI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
Other sources
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox Cloud 24.1, FortiSandbox Cloud 23 all versions allows a remote privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53679?
CVE-2025-53679 is classified as a high-severity vulnerability due to its ability to allow remote privileged attackers to execute unauthorized commands.
How do I fix CVE-2025-53679?
To fix CVE-2025-53679, update Fortinet FortiSandbox to version 5.0.3 or above, or to version 4.4.8 or above.
Which versions of Fortinet FortiSandbox are affected by CVE-2025-53679?
Versions 5.0.0 to 5.0.2 and versions before 4.4.7 of Fortinet FortiSandbox are affected by CVE-2025-53679.
Can CVE-2025-53679 be exploited remotely?
Yes, CVE-2025-53679 can be exploited remotely by privileged attackers through crafted HTTP requests.
What kind of vulnerability is CVE-2025-53679?
CVE-2025-53679 is an OS Command Injection vulnerability, which is a type of improper neutralization of special elements.