FortiSandbox

CVE-2024-54018: Multiple improper neutralization of special elements used in an OS Command in FortiSandbox

Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests.

Published

ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityMEDIUMCVSS 3.1 6.5
EPSS10%Chance of exploitation in 30 days
Public exploitNot tracked
FixAvailable

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
FortiSandbox 4.4.0 to 4.4.44.4.6 or later
FortiSandbox 4.2.1 to 4.2.6Upgrade past 4.2.6; see the advisory
FortiSandbox 4.0.0 to 4.0.6Upgrade past 4.0.6; see the advisory
FortiSandbox 3.2.0 to 3.2.4Upgrade past 3.2.4; see the advisory

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.