Executive brief
A vulnerability exists in the management interface of Fortinet FortiOS, the operating system used in FortiGate firewalls and other networking devices. An authorized administrator can send a specifically crafted request to the device's API that causes the web management service to crash. While this does not expose data, it can disrupt administrative access and management operations for the affected security appliance.
Technical details
An Unchecked Return Value vulnerability (CWE-252) exists in the FortiOS API component. The root cause is a failure to validate return values, which leads to a Null Pointer Dereference when processing specially crafted requests. An authenticated attacker with network access to the management API can exploit this to crash the 'httpsd' (HTTP daemon) process. This results in a partial denial of service affecting the administrative GUI and API availability. The vulnerability is fixed in FortiOS versions 7.6.4 and 7.4.9; users on older branches (7.2, 7.0, 6.4) are advised to migrate to a supported fixed release.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versions, 6.4 all versions
- Siemens RUGGEDCOM APE1808 (Fortinet NGFW) Versions prior to V7.4.9 or V7.6.6
Timeline
- 2025-10-14: disclosed: Initial publication by Fortinet
- 2025-10-14: advisory: Fortinet advisory FG-IR-25-653 published
- 2025-05-13: other: Siemens advisory SSA-864900 initially published (updated later with this CVE)