PT-2026-40110 · Fortinet · Fortiap-W2+1

Published

2026-05-12

·

Updated

2026-05-15

·

CVE-2025-53870

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiAP versions 7.6.0 through 7.6.2 FortiAP versions 7.4.0 through 7.4.5 FortiAP version 7.2 FortiAP version 7.0 FortiAP version 6.4 FortiAP-W2 versions 7.4.0 through 7.4.4 FortiAP-W2 version 7.2 FortiAP-W2 version 7.0
Description An OS command injection issue exists in the command line interface (CLI) of the firmware, where special elements used in operating system commands are not properly neutralized. This allows an authenticated attacker to execute unauthorized code or arbitrary commands via a specifically crafted CLI command. OS command injection is a flaw that allows an attacker to execute arbitrary operating system commands on the server running an application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-06793
CVE-2025-53870

Affected Products

Fortiap
Fortiap-W2