HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2021-26106

CVSS 7.8v3.1pub. 2021-07-09upd. 2024-11-21

An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 may allow an authenticated attacker to execute unauthorized commands by running the kdbg CLI command with specifically crafted arguments.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Fortinet Fortiap

    APP
    Fortinet
    6.4.1 – 6.4.6 (excl.)
  • Fortinet Fortiap S

    APP
    Fortinet
    6.2.4 – 6.2.6 (excl.)
  • Fortinet Fortiap W2

    APP
    Fortinet
    6.2.4 – 6.2.6 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2022-29058HIGH7.8same product

An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the co...

CVE-2019-17657HIGH7.5same product

An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, Fort...

CVE-2025-53870MEDIUM6.7same product

Podatność polegająca na niewłaściwej neutralizacji znaków specjalnych używanych w poleceniach systemu operacyj...

CVE-2025-53680MEDIUM6.7same product

Nieuprawniona neutralizacja specjalnych znaków używanych w poleceniach systemowych ("OS Command Injection") w ...

CVE-2024-26012MEDIUM6.7same product

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet Forti...