VYPR
Unrated severityNVD Advisory· Published Aug 12, 2025· Updated Feb 26, 2026

CVE-2025-53744

CVE-2025-53744

Description

An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the device to a malicious FortiManager.

Affected products

2
  • Fortinet/Fortiosv52 versions
    cpe:2.3:o:fortinet:fortios:7.6.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortios:7.6.2:*:*:*:*:*:*:*range: 7.6.0
    • (no CPE)range: 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all, 7.0 all, 6.4 all

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.