CVE-2025-53870: OS command injection in CLI
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-W2 7.4.0 through 7.4.4, FortiAP-W2 7.2 all versions, FortiAP-W2 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command.
Other sources
An OS command injection vulnerabtility [CWE-78] in FortiAP and FortiAP-W2 cli may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command.
— FortiGuard
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiAPto a version that resolves this vulnerability.Fixed in 7.4.6 - Upgrade
Upgrade
FortiAPto a version that resolves this vulnerability.Fixed in 7.6.3 - Upgrade
Upgrade
FortiAP-Uto a version that resolves this vulnerability.Fixed in 7.0.6 - Upgrade
Upgrade
FortiAP-W2to a version that resolves this vulnerability.Fixed in 7.4.5
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53870?
CVE-2025-53870 is classified as a high severity vulnerability due to the potential for OS command injection.
How do I fix CVE-2025-53870?
To mitigate CVE-2025-53870, upgrade Fortinet FortiAP to version 7.6.3 or later, or 7.4.6 or later for versions 7.4.0 through 7.4.5.
Which products are affected by CVE-2025-53870?
CVE-2025-53870 affects Fortinet FortiAP versions 7.0 and earlier, as well as FortiAP-W2 versions 7.4.0 through 7.4.5.
Is there a workaround for CVE-2025-53870?
There are no known workarounds for CVE-2025-53870; patching is recommended.
What kind of attacks can CVE-2025-53870 allow?
CVE-2025-53870 can allow attackers to execute arbitrary OS commands, leading to a range of potential exploits.