Junglewise Threat Intelligence

CVE-2025-53870: Fortinet FortiAP OS command injection in CLI

CVE-2025-53870 · Severity: medium · CVSS 6.7 · Published 2026-05-12

Vendors: Fortinet.

Executive brief

FortiAP is a wireless access point used to provide Wi-Fi connectivity in corporate environments. A security flaw in its command-line interface allows an authorized user with high-level access to run restricted system commands. This could lead to a full takeover of the device, potentially allowing an attacker to disrupt wireless services or gain a deeper foothold in the network.

Technical details

An OS command injection vulnerability (CWE-78) exists in the CLI component of Fortinet FortiAP and FortiAP-W2. The flaw is caused by improper neutralization of special elements within CLI commands. An authenticated attacker with high privileges can exploit this by submitting a specifically crafted command to execute arbitrary code at the operating system level. The attack vector is classified as local (AV:L) because it requires access to the device's management interface. Patches are available in FortiAP versions 7.6.3, 7.4.6, and FortiAP-W2 version 7.4.5.

Affected products

  • Fortinet FortiAP 7.6.0 through 7.6.2, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions
  • Fortinet FortiAP-W2 7.4.0 through 7.4.4, 7.2 all versions, 7.0 all versions

Timeline

  • 2026-05-12: disclosed: Initial publication by Fortinet
  • 2026-05-12: advisory: NVD entry created

References

Related threats