Vulnerability Details CVE-2025-25255
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiProxy 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0.1 through 7.0.21, and FortiOS 7.6.0 through 7.6.3 explicit web proxy may allow an authenticated proxy user to bypass the domain fronting protection feature via crafted HTTP requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.8%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2025-25255
-
cpe:2.3:a:fortinet:fortiproxy:7.0.1
-
cpe:2.3:a:fortinet:fortiproxy:7.0.10
-
cpe:2.3:a:fortinet:fortiproxy:7.0.11
-
cpe:2.3:a:fortinet:fortiproxy:7.0.12
-
cpe:2.3:a:fortinet:fortiproxy:7.0.13
-
cpe:2.3:a:fortinet:fortiproxy:7.0.14
-
cpe:2.3:a:fortinet:fortiproxy:7.0.15
-
cpe:2.3:a:fortinet:fortiproxy:7.0.16
-
cpe:2.3:a:fortinet:fortiproxy:7.0.17
-
cpe:2.3:a:fortinet:fortiproxy:7.0.18
-
cpe:2.3:a:fortinet:fortiproxy:7.0.19
-
cpe:2.3:a:fortinet:fortiproxy:7.0.2
-
cpe:2.3:a:fortinet:fortiproxy:7.0.20
-
cpe:2.3:a:fortinet:fortiproxy:7.0.21
-
cpe:2.3:a:fortinet:fortiproxy:7.0.3
-
cpe:2.3:a:fortinet:fortiproxy:7.0.4
-
cpe:2.3:a:fortinet:fortiproxy:7.0.5
-
cpe:2.3:a:fortinet:fortiproxy:7.0.6
-
cpe:2.3:a:fortinet:fortiproxy:7.0.7
-
cpe:2.3:a:fortinet:fortiproxy:7.0.8
-
cpe:2.3:a:fortinet:fortiproxy:7.0.9
-
cpe:2.3:a:fortinet:fortiproxy:7.2.0
-
cpe:2.3:a:fortinet:fortiproxy:7.2.1
-
cpe:2.3:a:fortinet:fortiproxy:7.2.10
-
cpe:2.3:a:fortinet:fortiproxy:7.2.11
-
cpe:2.3:a:fortinet:fortiproxy:7.2.12
-
cpe:2.3:a:fortinet:fortiproxy:7.2.13
-
cpe:2.3:a:fortinet:fortiproxy:7.2.14
-
cpe:2.3:a:fortinet:fortiproxy:7.2.2
-
cpe:2.3:a:fortinet:fortiproxy:7.2.3
-
cpe:2.3:a:fortinet:fortiproxy:7.2.4
-
cpe:2.3:a:fortinet:fortiproxy:7.2.5
-
cpe:2.3:a:fortinet:fortiproxy:7.2.6
-
cpe:2.3:a:fortinet:fortiproxy:7.2.7
-
cpe:2.3:a:fortinet:fortiproxy:7.2.8
-
cpe:2.3:a:fortinet:fortiproxy:7.2.9
-
cpe:2.3:a:fortinet:fortiproxy:7.4.0
-
cpe:2.3:a:fortinet:fortiproxy:7.4.1
-
cpe:2.3:a:fortinet:fortiproxy:7.4.2
-
cpe:2.3:a:fortinet:fortiproxy:7.4.3
-
cpe:2.3:a:fortinet:fortiproxy:7.4.4
-
cpe:2.3:a:fortinet:fortiproxy:7.4.5
-
cpe:2.3:a:fortinet:fortiproxy:7.4.6
-
cpe:2.3:a:fortinet:fortiproxy:7.4.7
-
cpe:2.3:a:fortinet:fortiproxy:7.4.8
-
cpe:2.3:a:fortinet:fortiproxy:7.4.9
-
cpe:2.3:a:fortinet:fortiproxy:7.6.0
-
cpe:2.3:a:fortinet:fortiproxy:7.6.1
-
cpe:2.3:a:fortinet:fortiproxy:7.6.2
-
cpe:2.3:a:fortinet:fortiproxy:7.6.3
-
cpe:2.3:o:fortinet:fortios:7.6.0
-
cpe:2.3:o:fortinet:fortios:7.6.1
-
cpe:2.3:o:fortinet:fortios:7.6.2
-
cpe:2.3:o:fortinet:fortios:7.6.3