Home

Description

An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiProxy 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0.1 through 7.0.21, and FortiOS 7.6.0 through 7.6.3 explicit web proxy may allow an authenticated proxy user to bypass the domain fronting protection feature via crafted HTTP requests.

PUBLISHED Reserved 2025-02-05 | Published 2025-10-14 | Updated 2025-10-15 | Assigner fortinet

Problem types

Improper access control

Product status

Default status
unaffected

7.6.0
affected

Default status
unaffected

7.6.0
affected

7.4.0
affected

7.2.0
affected

7.0.1
affected

References

fortiguard.fortinet.com/psirt/FG-IR-24-372

cve.org (CVE-2025-25255)

nvd.nist.gov (CVE-2025-25255)

Download JSON