CVE-2025-53844: Out-of-bounds access in CAPWAP daemon
A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets.
Other sources
An Out-Of-Bounds Write vulnerability [CWE-787] in FortiOS capwap daemon may allow an attacker controlling an authenticated FortiAP FortiExtender or FortiSwitch to gain execution privileges on the FortiGate device
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 7.0.18 - Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 7.2.12 - Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 7.4.9 - Upgrade
Upgrade
Fortinet FortiOSto a version that resolves this vulnerability.Fixed in 7.6.4 - Upgrade
Upgrade
Fortinet FortiSwitchManagerto a version that resolves this vulnerability.Fixed in 7.0.6 - Upgrade
Upgrade
Fortinet FortiSwitchManagerto a version that resolves this vulnerability.Fixed in 7.2.7
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53844?
CVE-2025-53844 has a critical severity rating due to the potential for unauthorized code execution.
How do I fix CVE-2025-53844?
To fix CVE-2025-53844, upgrade FortiOS to version 7.6.4 or higher, 7.4.9 or higher, or 7.2.12 or higher.
What types of devices are affected by CVE-2025-53844?
CVE-2025-53844 affects Fortinet FortiOS versions 7.6.0 to 7.6.3, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.11.
What is the cause of CVE-2025-53844?
CVE-2025-53844 is caused by an out-of-bounds write vulnerability in the CAPWAP daemon.
Can CVE-2025-53844 lead to remote code execution?
Yes, CVE-2025-53844 allows attackers to execute unauthorized code or commands through specially crafted packets.