Executive brief
A security vulnerability exists in the software used to manage wireless access points on Fortinet networking devices. An attacker located on the same local network could potentially take full control of the device by sending malicious data packets. While the attack is difficult to execute because it requires bypassing modern security protections, a successful exploit could lead to unauthorized access to the corporate network or a complete service outage.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in the CAPWAP (Control and Provisioning of Wireless Access Points) daemon of Fortinet FortiOS and FortiSASE. The flaw is triggered by processing specially crafted packets sent by an unauthenticated attacker on an adjacent network (same local IP subnet). In default configurations, the attacker must typically control an authorized FortiAP to reach the vulnerable component. Successful exploitation allows for arbitrary code execution, though it requires defeating exploit mitigations such as ASLR and stack canaries. Fortinet has released patches (e.g., FortiOS 7.6.4 and 7.4.9) and provided workarounds including disabling security fabric access on interfaces and removing inter-controller-peer elements.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions, 6.4 all versions, 6.2 all versions, 6.0 all versions
- Fortinet FortiSASE 25.3.b
- Siemens RUGGEDCOM APE1808 All versions with Fortinet NGFW < V7.4.9 or < V7.6.6
Timeline
- 2025-11-18: advisory: Initial publication by Fortinet
- 2025-11-18: disclosed
- 2025-11-21: other: Workarounds added to Fortinet advisory