CVE-2025-62826: Header injection in captive portal authentication form
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary headers via crafted HTTP requests.
Other sources
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept and modify a user's captive portal authentication request to inject arbitrary headers via crafted HTTP requests.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.5 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.5 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 8.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62826?
The severity of CVE-2025-62826 is rated as medium with a score of 4.3.
How do I fix CVE-2025-62826?
To fix CVE-2025-62826, update to the latest version of FortiOS or FortiProxy where the vulnerability has been patched.
What does CVE-2025-62826 affect?
CVE-2025-62826 affects Fortinet FortiOS and Fortinet FortiProxy captive portal authentication forms.
What type of vulnerability is CVE-2025-62826?
CVE-2025-62826 is an Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability.
What can an attacker do with CVE-2025-62826?
An attacker can use CVE-2025-62826 to inject arbitrary headers into a user's authentication request.