---
cve: "CVE-2025-55018"
severity: "MEDIUM"
cvss: 5.2
epss: "35%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2026-02-10 16:16:08"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T23:05:40+02:00"
---

# CVE-2025-55018

> 5.2 MEDIUM

## Beschreibung

An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4.3 through 6.4.16 may allow  an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially crafted header

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N/E:P/RL:O/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Keine | good |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://fortiguard.fortinet.com/psirt/FG-IR-25-667>
- <https://cert-portal.siemens.com/productcert/html/ssa-975644.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-55018) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
