A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.
The attacker sends specially crafted HTTP requests to the vulnerable FortiWLM server, exploiting improper handling of relative file paths (relative path traversal, CWE-23). This mechanism enables escaping the permitted file system area and accessing resources that should have restricted access. Combined with code injection and execution capabilities (CWE-94), the attacker can cause arbitrary commands to be executed on the server. The entire attack requires neither authentication nor user interaction.
An attacker can gain full control over the vulnerable system, including executing arbitrary code or system commands, which may lead to violations of confidentiality, integrity, and availability of the device and managed wireless infrastructure.
Fortinet FortiWLM should be updated to versions beyond the 8.5.x and 8.6.x branches in accordance with the manufacturer's recommendations available at https://fortiguard.com/psirt/FG-IR-23-144. Until a patch is deployed, it is recommended to restrict access to the FortiWLM management interface exclusively to trusted IP addresses.
Fortinet FortiWLM in versions 8.6.0 – 8.6.5 and 8.5.0 – 8.5.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HFortinet Fortiwlm
APPFortinet8.5.0 – 8.5.5 (excl.)8.6.0 – 8.6.6 (excl.)
Related vulnerabilities
SQL Injection w Fortinet FortiWLM umożliwiający wykonanie nieautoryzowanego kodu
Command injection w Fortinet FortiWLM umożliwiający zdalne wykonanie kodu
Command injection w Fortinet FortiWLM umożliwia zdalne wykonanie kodu
Command injection w Fortinet FortiWLM via parametry HTTP GET
Command injection w Fortinet FortiWLM umożliwiający RCE bez uwierzytelnienia