---
id: CVE-2025-53847
title: >-
  A missing authentication for critical function vulnerability in Fortinet
  FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0
  through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions,
  FortiOS 6.2.9 throug…
summary: >-
  A missing authentication for critical function vulnerability in Fortinet
  FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0
  through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions,
  FortiOS 6.2.9 throug…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-306
vendor: fortinet
product: fortios
affected:
  - 'fortios >= 6.2.9, < 7.0.18'
  - 'fortios >= 7.2.0, < 7.2.12'
  - 'fortios >= 7.4.0, < 7.4.9'
  - 'fortios >= 7.6.0, < 7.6.4'
patched:
  - fortios 7.6.4
published: '2026-04-14'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-53847'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-26-125'
    label: psirt@fortinet.com
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-975644.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.00283
epssPercentile: 0.18758
ingestedAt: '2026-09-30T22:27:27.754Z'
---

## Overview

A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.

## Affected

- `fortios >= 6.2.9, < 7.0.18`
- `fortios >= 7.2.0, < 7.2.12`
- `fortios >= 7.4.0, < 7.4.9`
- `fortios >= 7.6.0, < 7.6.4`

## Remediation

Upgrade past the affected range:

- `fortios 7.6.4`
