An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-W2 7.4.0 through 7.4.4, FortiAP-W2 7.2 all versions, FortiAP-W2 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-133 |
|
History
Tue, 12 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Neutralization of Special Elements in OS Command Injection in Fortinet FortiAP Devices |
Tue, 12 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-W2 7.4.0 through 7.4.4, FortiAP-W2 7.2 all versions, FortiAP-W2 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command. | |
| First Time appeared |
Fortinet
Fortinet fortiap Fortinet fortiap-w2 |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:fortinet:fortiap-w2:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.0.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.0.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.0.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.0.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.0.6:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.0.7:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.0.8:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.2.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.2.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.2.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.2.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.2.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.2.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.4.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.4.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.4.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.4.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap-w2:7.4.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:6.4.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:6.4.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:6.4.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:6.4.6:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:6.4.7:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:6.4.8:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:6.4.9:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.0.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.0.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.0.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.0.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.0.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.0.6:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.0.7:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.2.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.2.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.2.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.2.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.2.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.2.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.2.6:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.4.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.4.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.4.2:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.4.3:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.4.4:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.4.5:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.6.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.6.1:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiap:7.6.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fortinet
Fortinet fortiap Fortinet fortiap-w2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2026-05-13T03:58:24.463Z
Reserved: 2025-07-11T07:30:58.396Z
Link: CVE-2025-53870
Updated: 2026-05-12T19:01:45.473Z
Status : Awaiting Analysis
Published: 2026-05-12T18:16:36.140
Modified: 2026-05-12T18:57:02.307
Link: CVE-2025-53870
No data.
OpenCVE Enrichment
Updated: 2026-05-12T20:45:23Z