Buffer overread in authd and wad daemon
A buffer over-read vulnerability exists in the authentication daemon (authd) and web access daemon (wad) of FortiOS and FortiProxy devices in the captive portal authentication processing code. The vulnerability allows an authenticated attacker to read beyond allocated memory boundaries, potentially leaking sensitive data such as configuration information, credentials, or session tokens. The issue affects FortiOS versions 7.2 (all), 7.4.0–7.4.8, and 7.6.0–7.6.2; FortiProxy versions 7.2 (all), 7.4.0–7.4.13, and 7.6.0–7.6.5. Fixed versions are available for all affected branches.
- Valid user credentials or authenticated session on the FortiOS/FortiProxy device
- Network access to the captive portal authentication interface (typically TCP 80/443)
- Target device must be running affected FortiOS or FortiProxy versions (7.2.x, 7.4.0-7.4.8, 7.6.0-7.6.2 for FortiOS; 7.2.x, 7.4.0-7.4.13, 7.6.0-7.6.5 for FortiProxy)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/5ec4a8d7-f4aa-417f-a2b1-9452818ae08bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.