False Positive: Multiple Windows laptops incorrectly identified as Samsung Galaxy Android 5.0
Hi everyone,
I'm running into a frustrating issue with the Device Identification (IoT/OT detection) feature on our FortiGate. Multiple Windows laptops on our network are being incorrectly identified as Samsung Galaxy Android 5.0 devices.
Because of this, FortiGate is flagging a randomly list of potential IoT/OT vulnerabilities associated with Android Lollipop, which is obviously a huge false positive (especially since no one is bringing Android 5.0 devices to the network in 2026!).
Here are some key details about our environment:
-
The affected clients are purely Windows machines.
-
There are no Android emulators installed on these laptops.
-
This is happening across several different devices, which rules out a simple stale DHCP IP cache/re-use issue.
-
Checking the CLI (
diagnose user device), the MAC OUI belongs to Cloud Network Technology (standard for laptop Wi-Fi adapters), not Samsung.
Has anyone else encountered this specific false positive recently? Any insights on which common Windows applications might be spoofing this specific Android 5.0 User-Agent, or is this a known issue with the latest signature database?
Thanks in advance for any help or workarounds!

