Relative Path Traversal Vulnerability in FortiWAN Products

CVE-2021-26102

9.8CRITICAL

Key Information

Vendor
Fortinet
Status
Fortiwan
Vendor
CVE Published:
19 December 2024

Summary

CVE-2021-26102 is a critical relative path traversal vulnerability in FortiWAN that affects versions 4.5.7 and below as well as all versions of 4.4. This vulnerability enables a remote, non-authenticated attacker to exploit the system through crafted POST requests, leading to the deletion of specific configuration files. Such unauthorized access can reset the admin password to its factory default, posing significant risks to system security and management. Immediate action is recommended to mitigate these risks.

Affected Version(s)

FortiWAN <= 4.5.7

FortiWAN <= 4.4.1

Refferences

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.