Full Report
Fortinet security advisory (AV26-023) - Update 1
Analysis Summary
# Vulnerability: Multiple Critical Flaws in Fortinet Products (including FortiOS and FortiSIEM)
## CVE Details
- **CVE ID:** CVE-2025-25249, CVE-2025-47855, CVE-2025-64155
- **CVSS Score:** Up to 9.8 (Critical)
- **CWE:** CWE-122 (Heap-based Buffer Overflow), CWE-78 (OS Command Injection), CWE-284 (Improper Access Control)
## Affected Systems
- **Products:** FortiOS, FortiSASE, FortiSIEM, FortiSwitchManager, FortiFone.
- **Versions:**
- **FortiOS:** 7.6.0-7.6.3, 7.4.0-7.4.8, 7.2.0-7.2.11, 7.0.0-7.0.17, 6.4.0-6.4.16
- **FortiSASE:** 25.1.a.2, 25.2.b
- **FortiSIEM:** 7.4.0, 7.3.0-7.3.4, 7.2.0-7.2.6, 7.1.0-7.1.8, 7.0.0-7.0.4, 6.7.0-6.7.10
- **FortiSwitchManager:** 7.2.0-7.2.6, 7.0.0-7.0.5
- **FortiFone:** 7.0.0-7.0.1, 3.0.13-3.0.23
- **Configurations:** Systems running the `cw_acd` daemon or exposed administrative interfaces.
## Vulnerability Description
This advisory covers three primary critical vulnerabilities:
1. **CVE-2025-25249:** A heap-based buffer overflow vulnerability in the `cw_acd` daemon. This flaw allows a remote attacker to execute arbitrary code or cause a Denial of Service (DoS) via specially crafted packets.
2. **CVE-2025-64155:** An unauthenticated remote command injection flaw. This allows an attacker to execute system-level commands without valid credentials.
3. **CVE-2025-47855:** A flaw allowing unauthenticated access to local configuration files, leading to the exposure of sensitive system data.
## Exploitation
- **Status:** **Exploited in the wild** (CVE-2025-25249 added to CISA KEV on September 9, 2026).
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full data exposure/Command execution)
- **Integrity:** High (System modification)
- **Availability:** High (System crash/Total takeover)
## Remediation
### Patches
Fortinet recommends upgrading to the following versions or higher:
- **FortiOS:** Upgrade to 7.6.4, 7.4.9, 7.2.12, 7.0.18, or 6.4.17.
- **FortiSIEM:** Upgrade to 7.4.1, 7.3.5, 7.2.7, 7.1.9, 7.0.5, or 6.7.11.
- **FortiSwitchManager:** Upgrade to 7.2.7 or 7.0.6.
- **FortiFone:** Upgrade to 7.0.2 or 3.0.24.
### Workarounds
- Disable the `cw_acd` daemon if Wireless Controller features are not in use.
- Restrict administrative access to trusted internal IP addresses using Local-In policies or Firewall policies.
## Detection
- **Indicators of Compromise:** Monitor for unexpected crashes of the `cw_acd` process. Look for unauthorized configuration changes or suspicious administrative logins from unknown IP addresses.
- **Detection methods and tools:** Utilize FortiAnalyzer or external SIEMs to audit system logs for command execution patterns and buffer overflow signatures.
## References
- **Vendor Advisory (CVE-2025-25249):** hxxps[://]www[.]fortiguard[.]com/psirt/FG-IR-25-084
- **Vendor Advisory (CVE-2025-47855):** hxxps[://]www[.]fortiguard[.]com/psirt/FG-IR-25-260
- **Vendor Advisory (CVE-2025-64155):** hxxps[://]www[.]fortiguard[.]com/psirt/FG-IR-25-772
- **CISA KEV Catalog:** hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25249