CVE-2025-53680: Command injection in CLI
An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] in FortiAP, FortiAP-U & FortiAP-W2 CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53680?
CVE-2025-53680 is considered a high severity vulnerability due to the potential for unauthorized code execution.
How do I fix CVE-2025-53680?
To fix CVE-2025-53680, update your FortiAP devices to the latest versions specified in the vendor's advisory.
What products are affected by CVE-2025-53680?
CVE-2025-53680 affects various FortiAP models including FortiAP, FortiAP-U, and FortiAP-W2 across specific software versions.
Can CVE-2025-53680 be exploited remotely?
CVE-2025-53680 requires an authenticated privileged attacker, making it less likely to be exploited remotely.
Is there a workaround for CVE-2025-53680?
There is currently no known workaround for CVE-2025-53680, and applying the appropriate updates is recommended.