VDB
CVE-2025-64157
CVE-2025-64157
PUBLISHED
CVSS 5.199999809265137 MEDIUM
An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4.3 through 6.4.16 may allow an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially crafted header
EPSS 0.02% · 4.1th percentile
Risk Scores
CVSS v3.1
5.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N/E:P/RL:O/RC:C
EPSS Score
0.02%
4.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | FortiOS | 7.4.0, 7.2.0, 7.0.0 |
Timeline
- Feb 10, 2026 CVE Published
- Feb 11, 2026 EPSS Score
- Feb 11, 2026 PoC Published
- Feb 13, 2026 EPSS Score
- Feb 15, 2026 EPSS Score
- Feb 17, 2026 EPSS Score
- Feb 19, 2026 EPSS Score
- Feb 21, 2026 EPSS Score
- Feb 23, 2026 EPSS Score
- Feb 25, 2026 EPSS Score
- Feb 27, 2026 EPSS Score
- Mar 1, 2026 EPSS Score
References
- https://www.fortiguard.com/psirt/FG-IR-25-795 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-934 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-1052 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-384 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-093 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-661 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-528 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-667 advisory
- https://fortiguard.fortinet.com/psirt/FG-IR-25-667 url