CVE-2021-22126

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Mar 17, 2025
CWE ID 284

Summary

CVE-2021-22126 is a vulnerability affecting FortiWLC versions 8.5.2 and below, 8.4.8 and below, 8.3.3 to 8.3.2, and 8.2.7 to 8.2.6. This issue involves the use of hard-coded passwords, which can be exploited by local, authenticated attackers. By leveraging the default username and password, unauthorized users can gain root access to Meru APs and FortiAP-Us, potentially leading to significant security breaches and unauthorized network access. It is crucial for organizations using these FortiWLC versions to apply the necessary patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Fortinet FortiWLC

Affected Vendors

  • Fortinet