cbcvebase.
CVE-2021-26115
published 2024-12-19

CVE-2021-26115: An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged…

PriorityP346high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.79%
51.9th percentile
An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.An OS command injection (CWE-78) vulnerability in FortiWAN Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.

Affected

9 ranges
VendorProductVersion rangeFixed in
fortinetfortiwan< 4.5.84.5.8
fortinetfortiwan
fortinetfortiwan4.0.0 – 4.0.6
fortinetfortiwan4.1.1 – 4.1.3
fortinetfortiwan4.2.1 – 4.2.2
fortinetfortiwan4.2.5 – 4.2.7
fortinetfortiwan4.3.0 – 4.3.1
fortinetfortiwan4.4.0 – 4.4.1
fortinetfortiwan4.5.0 – 4.5.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.