Buffer Overflow in LLDP OUI field

Summary

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability [CWE-120] in FortiSwitchAXFixed may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a crafted LLDP packet.

Version Affected Solution
FortiSwitchAXFixed 1.0 1.0.0 through 1.0.1 Upgrade to 1.0.2 or above

Acknowledgement

Internally discovered and reported by Yonghui Han of Fortinet Product Security team.

Timeline

2026-03-10: Initial publication