FORTINET Security Advisory

Published Date: Not specified

Advisory Summary

🔔 ▲ Security Alert: Stack Buffer Overflow in FortiOS WAD (Explicit Proxy)

🧩 What’s happening
A stack-based buffer overflow (CWE-121) has been reported in FortiOS explicit proxy, affecting the WAD daemon. Under specific conditions, an attacker may be able to achieve remote code/command execution in the context of the WAD process by sending crafted sockets.

⚠️ Security hardening note
Because successful exploitation depends on bypassing stack protection/ASLR, your device posture and platform mitigations matter—but you should still treat this as a patch-now class risk for the affected configuration states.

📌

-121

Reference: Vendor Advisory