Junglewise Threat Intelligence

CVE-2025-53847: Fortinet FortiOS missing authentication in CAPWAP daemon

CVE-2025-53847 · Severity: medium · CVSS 6.5 · Published 2026-04-14

Technologies: Siemens Ruggedcom Ape1808, Fortinet FortiOS, Fortinet FortiSwitchManager. Vendors: Siemens, Fortinet.

Executive brief

Fortinet FortiOS is the operating system used by FortiGate firewalls and other networking hardware to manage security and connectivity. A vulnerability in the component that manages wireless access points could allow an attacker on the same local network to modify the device's configuration without needing a password. This could lead to unauthorized changes in security settings or the execution of unauthorized commands, potentially compromising the integrity of the network infrastructure.

Technical details

A missing authentication for critical function vulnerability (CWE-306) exists in the CAPWAP (Control and Provisioning of Wireless Access Points) daemon of Fortinet FortiOS and FortiSwitchManager. An unauthenticated attacker located on the same local IP subnet can exploit this by sending specially crafted packets to the daemon. Successful exploitation allows the attacker to write device configurations or execute unauthorized commands. The vulnerability requires a non-default configuration to be exploitable, specifically if 'auto-auth-extension-device' is enabled or if certain 'inter-controller-peer' settings are present. Patches are available in FortiOS versions 7.6.4, 7.4.9, 7.2.12, 7.0.18, and later.

Affected products

  • Fortinet FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.0 through 7.0.17, 6.4 all versions, 6.2.9 through 6.2.17
  • Fortinet FortiSwitchManager CAPWAP daemon component
  • Siemens RUGGEDCOM APE1808 All versions with Fortinet NGFW < V7.4.9

Timeline

  • 2026-03-10: advisory: Initial Siemens advisory publication
  • 2026-04-14: disclosed: Initial Fortinet publication
  • 2026-04-14: advisory: NVD published date
  • 2026-05-12: other: Siemens advisory updated to include this CVE

References

Related threats