CVE-2021-26115
published 2024-12-19CVE-2021-26115: An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged…
PriorityP346high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.79%
51.9th percentile
An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.An OS command injection (CWE-78) vulnerability in FortiWAN Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiwan | < 4.5.8 | 4.5.8 |
| fortinet | fortiwan | — | — |
| fortinet | fortiwan | 4.0.0 – 4.0.6 | — |
| fortinet | fortiwan | 4.1.1 – 4.1.3 | — |
| fortinet | fortiwan | 4.2.1 – 4.2.2 | — |
| fortinet | fortiwan | 4.2.5 – 4.2.7 | — |
| fortinet | fortiwan | 4.3.0 – 4.3.1 | — |
| fortinet | fortiwan | 4.4.0 – 4.4.1 | — |
| fortinet | fortiwan | 4.5.0 – 4.5.7 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a lo...
vendor_fortinet·2024-12-19·CVSS 7.8
CVE-2021-26115 [HIGH] CWE-78 An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a lo...
FG-IR-21-069: An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a lo...
An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.An OS command injection (CWE-78) vulnerability in FortiWAN Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.
CVEs: CVE-2021-26115
CWEs: CWE-78
CVSS: 7.8 (high)
Affected products: FortiWAN
GHSA
GHSA-f6w7-3cg5-fhr8: An OS command injection (CWE-78) vulnerability in FortiWAN version 4
ghsa_unreviewed·2024-12-19
CVE-2021-26115 [HIGH] CWE-78 GHSA-f6w7-3cg5-fhr8: An OS command injection (CWE-78) vulnerability in FortiWAN version 4
An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.An OS command injection (CWE-78) vulnerability in FortiWAN Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-19
Published