SQL Injection Vulnerability in FortiWAN by Fortinet
CVE-2021-26114
9.8CRITICAL
Summary
Multiple vulnerabilities in FortiWAN prior to version 4.5.9 enable an unauthenticated attacker to exploit improper neutralization of special elements in SQL commands. This could allow unauthorized command execution through specially crafted HTTP requests, posing significant security risks to affected systems.
Affected Version(s)
Fortinet FortiWAN FortiWAN before 4.5.9
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved