CVE-2025-53949 | Fortinet FortiSandbox up to 4.2.8/4.4.7/5.0.2 HTTP os command injection (FG-IR-25-479)
A vulnerability was found in Fortinet FortiSandbox up to 4.2.8/4.4.7/5.0.2. It has been declared as critical. Affected by this issue is some unknown functionality of the component HTTP Handler. Executing manipulation can lead to os command injection.
This vulnerability is handled as CVE-2025-53949. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.