Missing Authentication for critical function in CAPWAP daemon

0
36

CVSSv3 Score: 6.2

A missing authentication for critical function vulnerability [CWE-306] in FortiOS and FortiSwitchManager CAPWAP daemon may allow a local unauthenticated attacker on the same local IP subnet to write device configuration via specially crafted requests. To be successful, this attack requires the targeted FortiGate device to run a specific, non default configuration.

Revised on 2026-04-14 00:00:00

– Read more