cbcvebase.
CVE-2024-26012
published 2025-01-14

CVE-2024-26012: A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 through 6.4.9…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 through 6.4.9, FortiAP-W2 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.3, and 7.4.0 through 7.4.2, FortiAP 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.3, and 7.4.0 through 7.4.2 allow a local authenticated attacker to execute unauthorized code via the CLI.

Affected

19 ranges
VendorProductVersion rangeFixed in
fortinetfortiap
fortinetfortiap>= 6.4.1 < 7.2.47.2.4
fortinetfortiap6.4.3 – 6.4.9
fortinetfortiap7.0.0 – 7.0.7
fortinetfortiap7.2.0 – 7.2.3
fortinetfortiap>= 7.4.0 < 7.4.37.4.3
fortinetfortiap7.4.0 – 7.4.2
fortinetfortiap-s
fortinetfortiap-s>= 6.2.0 < 6.4.106.4.10
fortinetfortiap-s6.2.0 – 6.2.6
fortinetfortiap-s6.4.0 – 6.4.9
fortinetfortiap-w2
fortinetfortiap-w2>= 6.4.0 < 7.2.47.2.4
fortinetfortiap-w26.4.0 – 6.4.10
fortinetfortiap-w27.0.0 – 7.0.8
fortinetfortiap-w27.2.0 – 7.2.3
fortinetfortiap-w2>= 7.4.0 < 7.4.37.4.3
fortinetfortiap-w27.4.0 – 7.4.2
fortinetfortinet