CVE-2021-26102

Severity
9.1CRITICAL
EPSS
60.8%
top 1.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19

Description

A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset the Admin password to its default value.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortiwan4.4.04.5.8
CVEListV5fortinet/fortiwan4.5.04.5.7+1

🔴Vulnerability Details

2
CVEList
CVE-2021-26102: A relative path traversal vulnerability (CWE-23) in FortiWAN version 42024-12-19
GHSA
GHSA-wwq6-xmjh-4f52: A relative path traversal vulnerability (CWE-23) in FortiWAN version 42024-12-19

📋Vendor Advisories

1
Fortinet
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remot...2024-12-19
CVE-2021-26102 (CRITICAL CVSS 9.1) | A relative path traversal vulnerabi | cvebase.io