PT-2025-36575 · Fortinet · Fortiap-W2+2

Published

2025-09-09

·

Updated

2026-05-15

·

CVE-2025-53680

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiAP versions 7.6.0 through 7.6.2 FortiAP versions 7.4.0 through 7.4.5 FortiAP version 7.2 FortiAP version 7.0 FortiAP version 6.4 FortiAP-U versions 7.0.0 through 7.0.5 FortiAP-U version 6.2 FortiAP-W2 versions 7.4.0 through 7.4.4 FortiAP-W2 version 7.2 FortiAP-W2 version 7.0
Description An OS Command Injection issue exists where improper neutralization of special elements used in an OS command allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests. This issue has been actively exploited in real-world incidents.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-06794
CVE-2025-53680

Affected Products

Fortiap
Fortiap-U
Fortiap-W2