cbcvebase.
CVE-2021-26102
published 2024-12-19

CVE-2021-26102: A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete…

PriorityP268critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
16.36%
96.6th percentile
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset the Admin password to its default value.

Affected

4 ranges
VendorProductVersion rangeFixed in
fortinetfortiwan
fortinetfortiwan>= 4.4.0 < 4.5.84.5.8
fortinetfortiwan4.4.0 – 4.4.1
fortinetfortiwan4.5.0 – 4.5.7

Detection & IOCsextracted from sources · hover to see the quote

  • Look for unauthenticated crafted POST requests targeting FortiWAN that include relative path traversal sequences (e.g., '../') in request parameters, which may indicate an attempt to delete arbitrary files on the system.
  • Monitor for deletion of Admin configuration files on FortiWAN, as successful exploitation targeting specific configuration files will reset the Admin password to its default value — a strong indicator of compromise.
  • Flag any POST requests from unauthenticated (non-session) sources to FortiWAN endpoints that contain path traversal patterns (CWE-23 / CWE-22), particularly on FortiWAN versions 4.5.7 and below or any 4.4.x version.
  • ·The vulnerability is exploitable without authentication (CWE-305 — Missing Authentication for Critical Function), meaning no valid session or credentials are required to trigger the file deletion via POST request.
  • ·Affected scope is FortiWAN 4.5.7 and all prior versions in the 4.5.x line, as well as all versions in the 4.4.x line. CVSS score is 9.8 (Critical), indicating high exploitability and impact.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.