CVE-2025-53847

A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

History

20 Apr 2026, 18:04

Type Values Removed Values Added
References () https://fortiguard.fortinet.com/psirt/FG-IR-26-125 - () https://fortiguard.fortinet.com/psirt/FG-IR-26-125 - Vendor Advisory
CPE cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
First Time Fortinet
Fortinet fortios

14 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-14 16:16

Updated : 2026-04-20 18:04


NVD link : CVE-2025-53847

Mitre link : CVE-2025-53847

CVE.ORG link : CVE-2025-53847


JSON object : View

Products Affected

fortinet

  • fortios
CWE
CWE-306

Missing Authentication for Critical Function