cbcvebase.
CVE-2021-26112
published 2022-04-06

CVE-2021-26112: Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpreter of FortiWAN before 4.5.9 may allow…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.64%
73.7th percentile
Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpreter of FortiWAN before 4.5.9 may allow an unauthenticated attacker to potentially corrupt control data in memory and execute arbitrary code via specifically crafted requests.

Affected

3 ranges
VendorProductVersion rangeFixed in
fortinetfortinet_fortiwan
fortinetfortiwan<= 4.5.8
fortinetfortiwan

Detection & IOCsextracted from sources · hover to see the quote

  • Target FortiWAN network daemons for stack-based buffer overflow attempts via specially crafted network requests from unauthenticated attackers
  • Monitor FortiWAN command line interpreter for stack-based buffer overflow exploitation attempts from unauthenticated sources
  • ·Vulnerability affects FortiWAN versions before 4.5.9; verify patched version is 4.5.9 or later to confirm remediation

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.