CVE-2026-22627
Received
Received - Intake
Buffer Overflow in Fortinet FortiSwitchAXFixed Enables Remote Code Execution
Publication date: 2026-03-10
Last updated on: 2026-04-09
Assigner: Fortinet, Inc.
Description
Description
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a crafted LLDP packet.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortiswitchaxfixed | From 1.0.0 (inc) to 1.0.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-120 | The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer. |