<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>OS command injections via GET request parameter</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-25-501</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2025-08-12T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2025-08-12T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2025-08-12T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An improper neutralization of special elements used in an OS Command (&#39;OS Command Injection&#39;) vulnerability [CWE-78] in FortiADC may allow a remote and authenticated attacker with low privilege to execute unauthorized code via specifically crafted HTTP parameters.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Execute unauthorized code or commands
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiADC 8.0 all versions are not affectedFortiADC 7.6 all versions are not affectedFortiADC 7.4 all versions are not affectedFortiADC version 7.2.0FortiADC version 7.1.0 through 7.1.1FortiADC 7.0 all versions are not affectedFortiADC 6.2 all versions
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiADC version 7.2.1 or abovePlease upgrade to FortiADC version 7.1.2 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is pleased to thank security researcher CataLpa from Dbappsecurity Co. Ltd for discovering and reporting this vulnerability under responsible disclosure.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiADC" Type="Product Name">
                <Branch Name="7.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.2.0">FortiADC 7.2.0</FullProductName>
                </Branch>
                <Branch Name="7.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.1.1">FortiADC 7.1.1</FullProductName>
                </Branch>
                <Branch Name="7.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-7.1.0">FortiADC 7.1.0</FullProductName>
                </Branch>
                <Branch Name="6.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.6">FortiADC 6.2.6</FullProductName>
                </Branch>
                <Branch Name="6.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.5">FortiADC 6.2.5</FullProductName>
                </Branch>
                <Branch Name="6.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.4">FortiADC 6.2.4</FullProductName>
                </Branch>
                <Branch Name="6.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.3">FortiADC 6.2.3</FullProductName>
                </Branch>
                <Branch Name="6.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.2">FortiADC 6.2.2</FullProductName>
                </Branch>
                <Branch Name="6.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.1">FortiADC 6.2.1</FullProductName>
                </Branch>
                <Branch Name="6.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiADC-6.2.0">FortiADC 6.2.0</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>OS command injections via GET request parameter</Title>
        <cvrf:CVE>CVE-2025-49813</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiADC-7.2.0</ProductID>
                <ProductID>FortiADC-7.1.1</ProductID>
                <ProductID>FortiADC-7.1.0</ProductID>
                <ProductID>FortiADC-6.2.6</ProductID>
                <ProductID>FortiADC-6.2.5</ProductID>
                <ProductID>FortiADC-6.2.4</ProductID>
                <ProductID>FortiADC-6.2.3</ProductID>
                <ProductID>FortiADC-6.2.2</ProductID>
                <ProductID>FortiADC-6.2.1</ProductID>
                <ProductID>FortiADC-6.2.0</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>6.6</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-25-501</URL>
                <Description>OS command injections via GET request parameter</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>