OS Command Injection Vulnerability in FortiWAN Products
CVE-2021-26115

7.8HIGH

Key Information:

Vendor

Fortinet

Status
Vendor
CVE Published:
19 December 2024

What is CVE-2021-26115?

CVE-2021-26115 is a high-severity OS command injection vulnerability affecting FortiWAN versions 4.5.7 and earlier. This security flaw resides in the Command Line Interface (CLI), enabling local, authenticated, and unprivileged attackers to execute specially-crafted commands. By exploiting this vulnerability, attackers can escalate their privileges to root, potentially gaining unauthorized access and control over affected systems. It is crucial for users and administrators of FortiWAN products to apply available patches and mitigate risks associated with this vulnerability. For more detailed information, refer to Fortinet's official advisory at FortiGuard.

Affected Version(s)

FortiWAN 4.5.0 <= 4.5.7

FortiWAN 4.4.0 <= 4.4.1

FortiWAN 4.3.0 <= 4.3.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-26115 : OS Command Injection Vulnerability in FortiWAN Products