CVE-2025-53847
high
CVSS v3
8.8
CVSS v2
—
VIR risk
8.8
Description
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.
Predictions
Exploit likelihood
82%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@fortinet.com — https://fortiguard.fortinet.com/psirt/FG-IR-26-125
References
CWEs
CWE-306
Verify integrity in audit chain (admin only). AS-IS.