Incorrect Privilege Assignment in Fortinet FortiOS Security Fabric
CVE-2025-53744

6.8MEDIUM

Key Information:

Vendor

Fortinet

Status
Vendor
CVE Published:
12 August 2025

What is CVE-2025-53744?

A vulnerability in FortiOS Security Fabric allows a remote authenticated attacker with high privileges to escalate their privileges to super-admin by registering the device to a malicious FortiManager. This incorrect privilege assignment can potentially lead to unauthorized access and control over the system, posing significant risks to the security of network assets.

Affected Version(s)

FortiOS 7.6.0 <= 7.6.2

FortiOS 7.4.0 <= 7.4.7

FortiOS 7.2.0 <= 7.2.11

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.