MEDIUM🇵🇱 Wersja polska

CVE-2025-53870

CVSS 6.7v3.1pub. 2026-05-12upd. 2026-05-15

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-W2 7.4.0 through 7.4.4, FortiAP-W2 7.2 all versions, FortiAP-W2 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Fortinet Fortiap

    APP
    Fortinet
    6.4.0 – 7.4.6 (excl.)7.6.0 – 7.6.3 (excl.)
  • Fortinet Fortiap W2

    APP
    Fortinet
    7.2.0 – 7.2.6 (excl.)7.4.0 – 7.4.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2022-29058HIGH7.8same product

An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the co...

CVE-2021-26106HIGH7.8same product

An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 ...

CVE-2019-17657HIGH7.5same product

An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, Fort...

CVE-2025-53680MEDIUM6.7same product

Nieuprawniona neutralizacja specjalnych znaków używanych w poleceniach systemowych ("OS Command Injection") w ...

CVE-2024-26012MEDIUM6.7same product

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet Forti...