Junglewise Threat Intelligence

CVE-2025-64157: Fortinet FortiOS format string vulnerability in CAPWAP fast-failover mode

CVE-2025-64157 · Severity: medium · CVSS 6.7 · Published 2026-02-10

Technologies: Siemens Ruggedcom Ape1808, Fortinet FortiOS, Fortinet FortiGate NGFW. Vendors: Siemens, Fortinet.

Executive brief

A vulnerability in Fortinet's FortiOS operating system, used in FortiGate firewalls and Siemens industrial application platforms, could allow an administrator to execute unauthorized commands. By providing a specially crafted configuration, a user with high-level access can bypass intended security restrictions to run arbitrary code. This could lead to a full compromise of the device's integrity and availability, though it requires the attacker to already have administrative credentials.

Technical details

A Use of Externally-Controlled Format String vulnerability (CWE-134) exists in the CAPWAP fast-failover mode component of FortiOS. The flaw is accessible via the Command Line Interface (CLI) and is triggered when the system processes specifically crafted configuration data. An attacker with administrative privileges can exploit this to achieve arbitrary code execution on the underlying operating system. The vulnerability affects multiple major versions of FortiOS (7.0, 7.2, 7.4, and 7.6) and is also present in Siemens RUGGEDCOM APE1808 devices running affected FortiOS versions. Patches are available in FortiOS 7.6.5, 7.4.10, and subsequent releases.

Affected products

  • Fortinet FortiOS 7.6.0 through 7.6.4, 7.4.0 through 7.4.9, 7.2.0 through 7.2.11, 7.0 all versions
  • Siemens RUGGEDCOM APE1808 (Fortigate NGFW) Versions with FortiOS < 7.4.10

Timeline

  • 2026-02-10: disclosed: Initial publication by Fortinet
  • 2026-02-10: advisory: Fortinet advisory FG-IR-25-795 published
  • 2026-03-10: advisory: Siemens advisory SSA-975644 published

References

Related threats