Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-53744

CVE-2025-53744: Fortinet FortiOS Privilege Escalation Flaw

CVE-2025-53744 is a privilege escalation vulnerability in Fortinet FortiOS Security Fabric that lets authenticated attackers gain super-admin access. This article covers technical details, affected versions, and mitigations.

Published:

CVE-2025-53744 Overview

CVE-2025-53744 is an incorrect privilege assignment vulnerability [CWE-266] in the FortiOS Security Fabric component. The flaw allows a remote authenticated attacker holding high privileges to escalate to super-admin by registering the device to a malicious FortiManager instance. Fortinet published the advisory under reference FG-IR-25-173.

Affected releases span FortiOS Security Fabric 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, and all versions of 7.2, 7.0, and 6.4.

Critical Impact

Authenticated administrative attackers can obtain super-admin privileges on FortiOS devices, providing full control over firewall policy, routing, and connected Security Fabric assets.

Affected Products

  • FortiOS Security Fabric 7.6.0 through 7.6.2
  • FortiOS Security Fabric 7.4.0 through 7.4.7
  • FortiOS Security Fabric 7.2, 7.0, and 6.4 (all versions)

Discovery Timeline

  • 2025-08-12 - CVE-2025-53744 published to NVD
  • 2025-08-15 - Last updated in NVD database

Technical Details for CVE-2025-53744

Vulnerability Analysis

The vulnerability resides in the FortiOS Security Fabric registration workflow with FortiManager. FortiOS assigns privileges incorrectly when a device registers to a FortiManager instance controlled by an attacker. An authenticated administrator with high privileges can leverage this registration path to be granted super-admin rights on the FortiOS device.

Because the Security Fabric trusts privilege metadata associated with the FortiManager registration, the device elevates the attacker's role beyond what their original account permitted. This effectively breaks the privilege separation between standard administrators and super-admin accounts. The attack is performed over the network and does not require user interaction.

Root Cause

The root cause is improper privilege assignment [CWE-266] during FortiManager registration. FortiOS does not adequately validate or constrain the privilege level returned during the registration handshake. As a result, role information supplied through a malicious FortiManager is honored by the FortiOS authorization layer.

Attack Vector

Exploitation requires an attacker who already holds a high-privileged administrative account on the FortiOS device. The attacker directs the device to register with a FortiManager under their control. During registration, the malicious FortiManager supplies privilege data that FortiOS accepts, elevating the attacker's session to super-admin. From there the attacker can modify firewall rules, disable logging, pivot through the Security Fabric, and persist on the device.

No public proof-of-concept code is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Refer to the Fortinet Security Advisory FG-IR-25-173 for vendor technical detail.

Detection Methods for CVE-2025-53744

Indicators of Compromise

  • Unexpected FortiManager registration events in FortiOS system logs, particularly where the FortiManager IP or serial number is not part of the approved management infrastructure.
  • Administrator accounts whose effective role transitions to super-admin without an authorized change request.
  • Outbound connections from FortiOS management interfaces to unknown FortiManager endpoints on TCP 541 or 542.

Detection Strategies

  • Audit config system central-management and Security Fabric settings for FortiManager entries that do not match the documented management baseline.
  • Correlate administrator login events with subsequent privilege changes and FortiManager registration attempts to surface anomalous sequences.
  • Alert on configuration changes that modify trusted hosts, admin profiles, or Security Fabric topology shortly after a registration event.

Monitoring Recommendations

  • Forward FortiOS event and audit logs to a SIEM and retain administrator activity for at least 90 days to support forensic review.
  • Monitor egress firewall rules to ensure FortiOS devices can only reach approved FortiManager management addresses.
  • Track Security Fabric membership changes and generate alerts when a downstream FortiGate registers with a new upstream device.

How to Mitigate CVE-2025-53744

Immediate Actions Required

  • Upgrade FortiOS to a fixed release as specified in Fortinet PSIRT advisory FG-IR-25-173.
  • Review all administrator accounts and revoke any unexpected super-admin privileges granted to non-approved users.
  • Restrict FortiManager registration to a curated list of trusted management hosts via the set fmg and trusted host configuration.

Patch Information

Fortinet has released fixes documented in advisory FG-IR-25-173. Customers running FortiOS Security Fabric 7.6.0 through 7.6.2 and 7.4.0 through 7.4.7 should move to the patched builds listed in the advisory. Versions 7.2, 7.0, and 6.4 are affected across all releases and should be migrated to a supported, patched branch.

Workarounds

  • Disable Security Fabric on devices that do not require it by clearing config system csf parameters until patching is complete.
  • Enforce trusted host restrictions on all administrative accounts to limit which source addresses can authenticate to FortiOS.
  • Require multi-factor authentication for high-privilege administrators to raise the cost of obtaining the prerequisite access needed for exploitation.
bash
# Configuration example: restrict central management to a known FortiManager
config system central-management
    set type fortimanager
    set fmg "<trusted-fortimanager-ip>"
    set serial-number "<trusted-fmg-serial>"
end

# Restrict admin source addresses
config system admin
    edit "admin"
        set trusthost1 <management-subnet>/24
    next
end

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.