CVE-2024-26012

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 through 6.4.9, FortiAP-W2 6.4 all versions, 7.0 all versi

Severity
Medium 6.3
CVSS 3.1
Exploited
Not listed
EPSS
0.007
51.4th percentile
Discovered by
Third party
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet

Description

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 through 6.4.9, FortiAP-W2 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.3, and 7.4.0 through 7.4.2, FortiAP 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.3, and 7.4.0 through 7.4.2 allow a local authenticated attacker to execute unauthorized code via the CLI.

Weakness: CWE-78

Affected products

Vendor Product Category Matched by
Fortinet FortiAP Routing & Switching cna-assigner
Vendor-reported products (3)
  • Fortinet · FortiAP-S
  • Fortinet · FortiAP-W2
  • Fortinet · FortiAP

Credit

Fortinet is pleased to thank Christian Hilgers from indevis for reporting this vulnerability under responsible disclosure

Vendor remediation

Please upgrade to FortiAP-S version 6.4.10 or above Please upgrade to FortiAP-W2 version 7.4.3 or above Please upgrade to FortiAP-W2 version 7.2.4 or above Please upgrade to FortiAP version 7.4.3 or above Please upgrade to FortiAP version 7.2.4 or above

Something wrong here?