SQL Injection Vulnerability in FortiWAN by Fortinet
CVE-2021-26114

9.8CRITICAL

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
6 April 2022

Summary

Multiple vulnerabilities in FortiWAN prior to version 4.5.9 enable an unauthenticated attacker to exploit improper neutralization of special elements in SQL commands. This could allow unauthorized command execution through specially crafted HTTP requests, posing significant security risks to affected systems.

Affected Version(s)

Fortinet FortiWAN FortiWAN before 4.5.9

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.