CVE-2025-53744 is an incorrect privilege assignment vulnerability (CWE-266) in FortiOS Security Fabric versions 7.6.0-7.6.2, 7.4.0-7.4.7, and all versions of 7.2, 7.0, and 6.4. This flaw allows a remote authenticated attacker with high privileges to escalate to super-admin by registering the device to a malicious FortiManager. Rated 7.2 HIGH, this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, including an article from CSO Online, indicating awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.4.0, < 7.4.8CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 7.6.0, < 7.6.3CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 6.4.0, <= 6.4.16CPE match | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 7.0.0, <= 7.0.17CPE match | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 7.2.0, <= 7.2.11CPE match | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.