CVE-2025-53847

MEDIUM

Fortinet FortiOS <7.6.3 - Auth Bypass

Title source: llm
STIX 2.1

Description

A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 16.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (7)
Fortinet/FortiOS 6.2.9 - 6.2.17
fortinet/fortios 6.2.9 - 7.0.18
Fortinet/FortiOS 6.4.0 - 6.4.16
Fortinet/FortiOS 7.0.0 - 7.0.17
Fortinet/FortiOS 7.2.0 - 7.2.11
Fortinet/FortiOS 7.4.0 - 7.4.8
Fortinet/FortiOS 7.6.0 - 7.6.3
Published Apr 14, 2026
Tracked Since Apr 14, 2026