CVE-2025-53844: A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, F...
A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets.
Security readout for executives and security teams
Plain-English summary
A memory-safety flaw in affected FortiOS versions could let a low-privileged network attacker run unauthorized code or commands using specially crafted packets. Successful exploitation could compromise confidentiality, integrity, and availability of a security appliance, creating risk to traffic and networks it protects.
Executive priority
Prioritize an accelerated inventory and vendor-guided remediation cycle. Internet-facing, externally reachable, or broadly accessible appliances should be addressed first. The high potential impact justifies prompt action, although the supplied evidence does not establish active exploitation.
Technical view
CVE-2025-53844 is a CWE-787 out-of-bounds write with CVSS 3.1 score 8.3. The supplied vector indicates network access, low complexity, low privileges, no user interaction, unchanged scope, and high confidentiality, integrity, and availability impacts.
Likely exposure
Exposure exists where FortiOS matches the enumerated affected CPEs: 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17, 6.4.0–6.4.16, 6.2.0–6.2.17, or 6.0.0–6.0.18. Reachability by low-privileged attackers increases concern.
Exploitation context
The CVSS vector reports proof-of-concept exploit maturity, but the supplied bundle marks this CVE as absent from KEV and provides no evidence of active exploitation. Treat exploitation as plausible, not confirmed in the wild.
Researcher notes
The bundle contains broader affected CPE ranges than the abbreviated description, so exposure decisions should use the complete CVE record and Fortinet advisory. No packet format, affected subsystem, fixed release, or vendor workaround is included here. The Siemens reference is present, but the bundle does not establish additional affected products.
Mitigation direction
Inventory FortiOS appliances and record their exact installed versions.
Review Fortinet advisory FG-IR-26-123 for supported upgrade targets or vendor mitigations.
Prioritize remediation for reachable appliances and those accessible to low-privileged users.
Apply vendor-supported remediation through normal backup, testing, and change-control procedures.
Monitor Fortinet guidance for revisions because the record was recently updated.
Validation and detection
Compare every appliance version with the complete affected ranges in the CVE record.
Confirm remediated versions or mitigations against Fortinet advisory FG-IR-26-123.
Verify appliances restarted successfully and retained intended security policies after remediation.
Review device and security logs for unexplained commands, crashes, or configuration changes.
Re-scan assets and document any accepted exceptions or unsupported versions.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-787: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
2ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-787 · source CWE mapping
Out-of-bounds Write
Out-of-bounds Write represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.