{"id":"CVE-2025-53680","title":"An improper neutralization of special elements used in an OS command (\"OS Command Injection\") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.…","summary":"An improper neutralization of special elements used in an OS command (\"OS Command Injection\") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.…","severity":"medium","cvss":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"fortinet","product":"fortiap","affected":["fortiap >= 6.4.0, < 7.4.6","fortiap >= 7.6.0, < 7.6.3","fortiap-u >= 7.0.0, < 7.0.6","fortiap-w2 >= 7.2.0, < 7.4.5"],"patched":["fortiap 7.6.3","fortiap-u 7.0.6","fortiap-w2 7.4.5"],"published":"2026-05-12","updated":"2026-07-08","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-53680","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-131","label":"psirt@fortinet.com"}],"tags":["nvd"],"epss":0.00561,"epssPercentile":0.45445,"ingestedAt":"2026-07-08T14:51:15.656Z","slug":"CVE-2025-53680","body":"## Overview\n\nAn improper neutralization of special elements used in an OS command (\"OS Command Injection\") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-U 7.0.0 through 7.0.5, FortiAP-U 6.2 all versions, FortiAP-W2 7.4.0 through 7.4.4, FortiAP-W2 7.2 all versions, FortiAP-W2 7.0 all versions allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.\n\n## Affected\n\n- `fortiap >= 6.4.0, < 7.4.6`\n- `fortiap >= 7.6.0, < 7.6.3`\n- `fortiap-u >= 7.0.0, < 7.0.6`\n- `fortiap-w2 >= 7.2.0, < 7.4.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fortiap 7.6.3`\n- `fortiap-u 7.0.6`\n- `fortiap-w2 7.4.5`","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":36.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}