CVE-2025-53847
published 2026-04-14CVE-2025-53847: A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through…
PriorityP357high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.28%
20.2th percentile
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.2.9 < 7.0.18 | 7.0.18 |
| fortinet | fortios | 6.2.9 – 6.2.17 | — |
| fortinet | fortios | 6.4.0 – 6.4.16 | — |
| fortinet | fortios | 7.0.0 – 7.0.17 | — |
| fortinet | fortios | >= 7.2.0 < 7.2.12 | 7.2.12 |
| fortinet | fortios | 7.2.0 – 7.2.11 | — |
| fortinet | fortios | >= 7.4.0 < 7.4.9 | 7.4.9 |
| fortinet | fortios | 7.4.0 – 7.4.8 | — |
| fortinet | fortios | >= 7.6.0 < 7.6.4 | 7.6.4 |
| fortinet | fortios | 7.6.0 – 7.6.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Missing Authentication for critical function in CAPWAP daemon
vendor_fortinet·2026-04-14·CVSS 6.5
CVE-2025-53847 [MEDIUM] CWE-306 Missing Authentication for critical function in CAPWAP daemon
FG-IR-26-125: Missing Authentication for critical function in CAPWAP daemon
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.
CVEs: CVE-2025-53847
CWEs: CWE-306
CVSS: 6.5 (medium)
Affected products: FortiOS, Fortinet
GHSA
GHSA-v55w-rvx7-pq26: A missing authentication for critical function vulnerability in Fortinet FortiOS 7
ghsa_unreviewed·2026-04-14
CVE-2025-53847 [MEDIUM] CWE-306 GHSA-v55w-rvx7-pq26: A missing authentication for critical function vulnerability in Fortinet FortiOS 7
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-14
Published