CVE-2025-53847: A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, Forti...
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.
Security readout for executives and security teams
Plain-English summary
This vulnerability lets an unauthenticated attacker on an adjacent network send crafted packets to affected FortiOS versions and execute unauthorized code or commands. The published CVSS score is medium, but the business concern is that firewall operating systems are high-value control points.
Executive priority
Treat as a prioritized patch-management item for network security infrastructure. It is not listed as actively exploited in the supplied evidence, but affected firewalls can influence traffic control and trust boundaries.
Technical view
CVE-2025-53847 is a CWE-306 missing-authentication issue in Fortinet FortiOS. The CVSS 3.1 vector is AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N, indicating adjacent-network reachability, low complexity, no privileges, no user interaction, and high integrity impact.
Likely exposure
Organizations running FortiOS 7.6.0-7.6.3, 7.4.0-7.4.8, 7.2.0-7.2.11, 7.0.0-7.0.17, all 6.4 versions, or 6.2.9-6.2.17 should assume potential exposure until inventory confirms otherwise.
Exploitation context
The provided sources do not show CISA KEV listing or active exploitation. The CVSS vector indicates exploitation requires adjacent network access, not general remote internet reachability, but no authentication or user interaction is required.
Researcher notes
Evidence is limited to the CVE record, Fortinet PSIRT reference, and Siemens advisory reference. Do not assume internet-exploitable reachability from the CVSS vector; AV:A means adjacent network. Fixed versions are not included in the provided bundle.
Mitigation direction
Inventory FortiOS versions across firewalls and managed appliances.
Check Fortinet PSIRT FG-IR-26-125 for vendor-approved fixed versions or mitigations.
Apply Fortinet-recommended updates through standard change control.
Review the Siemens advisory if Siemens-managed or integrated deployments are present.
Limit untrusted adjacent-network access to FortiOS management and exposed interfaces where feasible.
Validation and detection
Confirm each FortiOS device version against the affected ranges.
Verify remediation status against Fortinet PSIRT FG-IR-26-125.
Check whether any Siemens advisory scope applies to your environment.
Review logs for unexpected configuration or command activity around exposed interfaces.
Document compensating controls for systems awaiting vendor-approved remediation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-306: Credential and account abuse lookup
Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-306 · source CWE mapping
Missing Authentication for Critical Function
Missing Authentication for Critical Function represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.