قاعدة الثغرات (CVE)
CVE-2026-25089
حقن أوامر نظام دون مصادقة في FortiSandbox
حرجةمُستغلة فعليًاKEVالتصحيح متوفر: غير متوفر بعد
ثغرة حقن أوامر في FortiSandbox وFortiSandbox Cloud وPaaS تسمح لمهاجم غير مصادَق بتنفيذ أوامر عبر طلبات HTTP مصمَّمة على منصة تحليل البرمجيات الخبيثة نفسها.
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests
المنتجات المتأثرة
| Product | الإصدارات المتأثرة | تم الإصلاح في |
|---|---|---|
| FortiSandbox | — | — |
التغطية على سيبرانا
—