An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0.1 through 7.0.22 may allow an unauthenticated proxy user to bypass the domain fronting protection feature via crafted HTTP requests.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-372 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-10-14 16:15
Updated : 2026-01-14 10:16
NVD link : CVE-2025-25255
Mitre link : CVE-2025-25255
CVE.ORG link : CVE-2025-25255
JSON object : View
Products Affected
fortinet
- fortiproxy
- fortios
CWE
CWE-358
Improperly Implemented Security Check for Standard
