Stack Buffer Overflow in CAPWAP Daemon Summary A stack-based overflow vulnerability (CWE-124) in FortiOS CAPWAP daemon may allow a remote unauthenticated attacker on an adjacent network to achieve arbitrary code execution via sending specially crafted packets. Note: In the default configuration, the attacker must be in control of an authorized FortiAP for the attack to succeed and have access to the same local IP subnet. Successful exploitation would require defeating stack protection and ASLR. Key Information IR Number FG-IR-25-632 Published Date 2025-11-18 Component OTHERS Severity Medium CVSSv3 Score 6.9 Impact Execute unauthorized code or commands CVE ID CVE-2025-58413 Affected Versions and Solutions Acknowledgement Internally discovered and reported by Gwendal Guégnaud of Fortinet Product Security team. Timeline 2025-11-18: Initial publication