CVE-2025-53847
Received
Received - Intake
Missing Authentication in FortiOS Allows Unauthorized Code Execution
Publication date: 2026-04-14
Last updated on: 2026-04-20
Assigner: Fortinet, Inc.
Description
Description
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fortinet | fortios | From 7.6.0 (inc) to 7.6.4 (exc) |
| fortinet | fortios | From 7.2.0 (inc) to 7.2.12 (exc) |
| fortinet | fortios | From 7.4.0 (inc) to 7.4.9 (exc) |
| fortinet | fortios | From 6.2.9 (inc) to 7.0.18 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |