CVE-2025-53680Disclosure(fortinet / fortiap)

LOWCVSS 6.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fortinet fortiap systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-U 7.0.0 through 7.0.5, FortiAP-U 6.2 all versions, FortiAP-W2 7.4.0 through 7.4.4, FortiAP-W2 7.2 all versions, FortiAP-W2 7.0 all versions allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiap
  • fortiap-u
  • fortiap-w2

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
fortiapfortiap-ufortiap-w2

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-14: 1Mentions · 2026-05-19: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-19: 105-1405-19
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-141
Disclosure1
2026-05-191
Patch1
Full discourse2 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: 1 critical, 1 high, 3 medium vulnerabilities in #Fortinet #FortiOS #FortiSandbox #FortiAP #FortiAnalyzer #FortiManager #CVE-2026-26083 #CVE-2025-53844 #CVE-2025-53870 #CVE-2025-53680 #CVE-2025-67604 CVSS: 9.8-5.3 See: https://www.fortiguard.com/psirt & https://ccb.belgium.be/advisories/warning-multiple-critical-high-and-medium-vulnerabilities-fortinet-fortisandbox-fortios

    Post summary

    The tweet announces five CVEs affecting Fortinet products with severity levels and CVSS scores, directing readers to official advisories.

    010101.6K
    7.2K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Fortinet 製品の脆弱性群が FIX:Critical な認可バイパスの脆弱性への対応が急務 https://iototsecnews.jp/2026/05/12/fortinet-patches-five-vulnerabilities-across-fortiap-fortios-and-enterprise-products/ 今回のセキュリティ・アドバイザリでは、認可の不備や入力値の検証不足が主な原因となっています。特に CVE-2026-26083 は、本来必要なはずの認可プロセスが欠落していたため、外部から認証なしで機密データに触れられてしまう状態でした。また CVE-2025-53680 や CVE-2025-53870 では、コマンド実行時の特殊文字に対する不適切な無効化が原因で、意図しない命令が実行されるリスクが生じています。ほかにも CVE-2025-67604 のように危険な関数の使用が原因となるものや、 CVE-2025-53844 のようにメモリへの書き込み範囲を正しく制限できていないケースも含まれています。ご利用のチームは、ご注意ください。#CVE202553680 #CVE202553844 #CVE202553870 #CVE202567604 #CVE202626083 #FortiAnalyzer #FortiAP #FortiManagerAPI #Fortinet #FortiOS #Vulnerability

    Post summary

    The advisory highlights several critical Fortinet product vulnerabilities—including authorization bypass and command injection—and urges users to apply the official patches immediately.

    01000158
    489 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiap---
Appfortinetfortiap-u---
Appfortinetfortiap-w2---

Explore more