OS Command Injection in administrative interface

Summary

Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox may allow a privileged attacker to execute unauthorized commands via crafted requests.

Version Affected Solution
FortiSandbox 5.0 Not affected Not Applicable
FortiSandbox 4.4 4.4.0 through 4.4.5 Upgrade to 4.4.6 or above
FortiSandbox 4.2 4.2 all versions Migrate to a fixed release
FortiSandbox 4.0 4.0 all versions Migrate to a fixed release
FortiSandbox 3.2 3.2 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Timeline

2025-03-11: Initial publication