cbcvebase.
CVE-2021-26093
published 2024-12-19

CVE-2021-26093: An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash…

PriorityP425medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.16%
5.6th percentile
An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access point being managed by the controller by executing a crafted CLI command.

Affected

10 ranges
VendorProductVersion rangeFixed in
fortinetfortiwlc
fortinetfortiwlc
fortinetfortiwlc
fortinetfortiwlc>= 8.0.6 < 8.6.38.6.3
fortinetfortiwlc8.1.2 – 8.1.3
fortinetfortiwlc8.2.4 – 8.2.7
fortinetfortiwlc8.3.0 – 8.3.3
fortinetfortiwlc8.4.0 – 8.4.2
fortinetfortiwlc8.4.4 – 8.4.8
fortinetfortiwlc8.5.0 – 8.5.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.