Executive brief
FortiOS is the operating system used by Fortinet security devices, such as firewalls, to manage network traffic and security policies. A vulnerability in this software could allow an attacker to send malicious network traffic to the device to gain unauthorized control. If exploited, this could lead to the execution of unauthorized commands, potentially compromising the security of the entire network or leading to data theft and service disruptions.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Fortinet FortiOS versions 7.6.0-7.6.3, 7.4.0-7.4.8, and 7.2.0-7.2.11. The flaw is triggered by the processing of specially crafted packets sent over the network. An attacker with low-level authentication (PR:L) can exploit this to achieve arbitrary code execution or unauthorized command execution on the underlying system. The vulnerability also impacts Siemens RUGGEDCOM APE1808 devices running affected Fortinet NGFW versions. Patches are available in FortiOS versions 7.6.6, 7.4.9, and 7.2.12.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11
- Siemens RUGGEDCOM APE1808 (Fortinet NGFW) Versions with Fortinet NGFW < V7.6.6
Timeline
- 2025-05-13: advisory: Initial Siemens advisory publication
- 2026-05-12: disclosed: NVD publication date
- 2026-06-09: other: Last modified date for NVD and Siemens records