
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-25249 is a heap-based buffer overflow vulnerability in the cw_acd daemon of Fortinet FortiOS and FortiSwitchManager that allows a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted packets. It was disclosed on January 13, 2026, and affects FortiOS 6.4 (all versions), 7.0.0–7.0.17, 7.2.0–7.2.11, 7.4.0–7.4.8, and 7.6.0–7.6.3; FortiSwitchManager 7.0.0–7.0.5 and 7.2.0–7.2.6; and FortiSASE versions 25.1.a.2 and 25.2.b. NVD assigns a CVSS v3.1 base score of 9.8 (Critical), while Fortinet's own CNA scoring is 8.1 (High), reflecting the mitigating effect of security controls such as ASLR and PIE (FortiGuard Advisory, NVD).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), rooted in insufficient bounds checking in the cw_acd (CAPWAP access controller daemon) within FortiOS and FortiSwitchManager (FortiGuard Advisory). An attacker can trigger the overflow by sending specially crafted network packets to the CAPWAP control port (UDP 5246–5249) on interfaces where the "fabric" access service is enabled, requiring no authentication or user interaction. Fortinet notes that the presence of ASLR and PIE security controls considerably raises the complexity and preparation effort required for successful exploitation, which is reflected in the vendor's lower CVSS score compared to NVD's assessment (FortiGuard Advisory). No public proof-of-concept exploit code has been identified as of the time of reporting (Feedly).
Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code or commands on the affected device, resulting in complete system compromise with high confidentiality, integrity, and availability impact. Affected assets include widely deployed Fortinet network security appliances (FortiOS-based firewalls and gateways, FortiSwitchManager, and FortiSASE), which are often positioned at network perimeters and management planes, making compromise a potential gateway for lateral movement into enterprise environments. An attacker gaining control of these devices could intercept or manipulate network traffic, exfiltrate sensitive configuration data, pivot to internal network segments, or cause denial of service (FortiGuard Advisory, Arctic Wolf).
As of the time of reporting, there is no known public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (FortiGuard Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term (Feedly). No specific threat actor attribution has been made. However, the unauthenticated, network-accessible nature of the flaw and the widespread deployment of FortiOS devices make it a high-priority target for future weaponization.
cw_acd daemon on UDP ports 5246–5249.cw_acd daemon's packet parsing logic.cw_acd daemon; unexpected error messages related to CAPWAP processing; authentication events from unknown sources on management interfaces.cw_acd daemon; unusual outbound connections initiated by FortiOS system processes to external IPs.Fortinet has released patched versions for all affected product lines: FortiOS should be upgraded to 7.6.4+, 7.4.9+, 7.2.12+, 7.0.18+, or 6.4.17+ (note: FortiOS 6.4 all versions are affected and users should migrate to a fixed release); FortiSwitchManager should be upgraded to 7.2.7+ or 7.0.6+; FortiSASE should be updated to 25.1.51 or 25.1.39 or later (FortiGuard Advisory). As an interim workaround, administrators can remove "fabric" access from each interface (eliminating exposure of the cw_acd daemon) or block CAPWAP control access to UDP ports 5246–5249 via a local-in policy, restricting access only to trusted managed device IPs. Fortinet provides a recommended upgrade path tool at https://docs.fortinet.com/upgrade-tool to assist with version transitions (FortiGuard Advisory).
The CIS (MS-ISAC) issued an advisory noting that multiple vulnerabilities in Fortinet products, including CVE-2025-25249, could allow for arbitrary code execution, urging organizations to apply patches promptly (CIS Advisory). Arctic Wolf published a threat intelligence blog post covering the vulnerability and recommending immediate patching (Arctic Wolf). Security news outlets including GBHackers, SecurityOnline, and Heise covered the disclosure, highlighting the critical nature of the unauthenticated RCE risk in widely deployed Fortinet infrastructure. Belgium's Centre for Cybersecurity (CCB) also issued a warning urging organizations to patch immediately (CCB Advisory). Community sentiment on social media and security forums reflects urgency given Fortinet's history of actively exploited vulnerabilities.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."