cbcvebase.
CVE-2017-7341
published 2017-10-26

CVE-2017-7341: An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management…

PriorityP347high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
3.90%
89.0th percentile
An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management AP script download webUI page allows an authenticated admin user to execute arbitrary system console commands via crafted HTTP requests.

Affected

6 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortiwlc
fortinetfortiwlc6.1-2 – 6.1-5
fortinetfortiwlc7.0-7 – 7.0-10
fortinetfortiwlc8.0 – 8.2
fortinetfortiwlc8.3.0 – 8.3.2

CVSS provenance

nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.