Executive brief
A security vulnerability exists in the software used to manage Fortinet firewalls and wireless access points. An attacker who can pose as a legitimate network device (like a wireless access point) could potentially take control of the firewall. This could lead to unauthorized access to the network, data theft, or a complete disruption of security operations.
Technical details
A stack-based buffer overflow vulnerability (CWE-121/CWE-124) exists in the CAPWAP (Control and Provisioning of Wireless Access Points) daemon of FortiOS and FortiSwitchManager. The flaw is triggered when the daemon processes specially crafted packets. To exploit this, an attacker must be authenticated and capable of posing as an authorized FortiAP or FortiExtender device. Successful exploitation allows for arbitrary code execution or command execution with the privileges of the CAPWAP process. While stack protection and ASLR increase the difficulty of exploitation, the vulnerability poses a significant risk if 'auto-auth-extension-device' is enabled, as it allows unauthorized devices to be automatically trusted. Patches are available in FortiOS versions 7.6.4 and 7.4.9.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions, 6.4 all versions
- Fortinet FortiSwitchManager All versions
- Siemens RUGGEDCOM APE1808 All versions with Fortinet NGFW < V7.4.9 or < V7.6.6
Timeline
- 2025-11-18: disclosed: Initial publication by Fortinet
- 2025-11-18: advisory
- 2025-11-21: other: Workarounds added to advisory