Vulnerabilities & Exploits
RUGGEDCOM APE1808 Devices Expose Unlogged HTTP Requests Siemens released an update for RUGGEDCOM APE1808 devices addressing Fortinet FortiOS HTTP request-smuggling flaws.
1 source · Mar 12
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet… EPSS 86% (100th percentile).
CISA federal remediation date Jan 30 · date passed
CVE-2025-64157 NVD KEV
CVSS 6.7 MEDIUM: a use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0… EPSS 1% (71st percentile).
CVE-2025-55018 NVD KEV
CVSS 5.8 MEDIUM: an inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0… EPSS 0.4% (30th percentile).
CVE-2025-62439 NVD KEV
CVSS 4.2 MEDIUM: an Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet… EPSS 0.1% (4th percentile).
Timeline Sources Vendor digest: Fortinet
Part of the PlainSec briefing for 2026-03-13
Every edition of this story: RUGGEDCOM APE1808 Devices Expose Unlogged HTTP Requests
More from today
Vulnerabilities & Exploits
RUGGEDCOM APE1808 Devices Expose Unlogged HTTP Requests Siemens released an update for RUGGEDCOM APE1808 devices addressing Fortinet FortiOS HTTP request-smuggling flaws.
1 source · Mar 12
NVD KEV
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet… EPSS 86% (100th percentile).
CISA federal remediation date Jan 30 · date passed
CVE-2025-64157 NVD KEV
CVSS 6.7 MEDIUM: a use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0… EPSS 1% (71st percentile).
CVE-2025-55018 NVD KEV
CVSS 5.8 MEDIUM: an inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0… EPSS 0.4% (30th percentile).
CVE-2025-62439 NVD KEV
CVSS 4.2 MEDIUM: an Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet… EPSS 0.1% (4th percentile).
Timeline Sources Vendor digest: Fortinet
Part of the PlainSec briefing for 2026-03-13
Every edition of this story: RUGGEDCOM APE1808 Devices Expose Unlogged HTTP Requests
More from today