Cyber Security News

FortiSandbox OS command injection Vulnerability Let Attackers execute Malicious code

Fortinet has released a critical security update for its FortiSandbox analysis appliances to fix a dangerous vulnerability.

If left unpatched, this flaw could allow attackers to take control of the underlying system. The vulnerability, tracked as CVE-2025-53949, was officially published on December 9, 2025.

The security flaw is described as an “OS Command Injection” vulnerability. In simple terms, this means the software does not correctly check the commands it receives before executing them.

This specific issue affects the Graphic User Interface (GUI) component of FortiSandbox. Because of this error, an attacker with system access (an “authenticated attacker”) could send specially crafted web requests to the device.

These bad requests trick the system into running malicious commands that it shouldn’t.

If successful, the attacker could execute unauthorized code, potentially stealing data, disrupting operations, or gaining further control over the network.

Fortinet has rated the severity of this issue as High, with a CVSS score of 7.0. While the attacker needs to be logged in to use this exploit, the potential damage is significant enough that administrators should act immediately.

The vulnerability affects several versions of FortiSandbox, including the 5.0, 4.4, 4.2, and 4.0 branches.

PropertyAffected VersionsFixed/Patched Versions
FortiSandbox 5.05.0.0 through 5.0.2Upgrade to 5.0.3
FortiSandbox 4.44.4.0 through 4.4.7Upgrade to 4.4.8
FortiSandbox 4.2All versions (4.2.x)Migrate to 5.0.3 or 4.4.8
FortiSandbox 4.0All versions (4.0.x)Migrate to 5.0.3 or 4.4.8

According to FortiGuard Labs, all organizations using these products should upgrade to the latest safe versions immediately.

Fortinet allows vendors to fix problems before hackers can exploit them widely. System administrators should review their FortiSandbox deployments immediately.

If you are running any of the versions listed above, schedule an upgrade window as soon as possible to protect your network infrastructure from potential attacks.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago