CVE-2021-26102
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 19, 2024
CWE ID 305
Summary
CVE-2021-26102 is a relative path traversal vulnerability (CWE-23) affecting FortiWAN versions 4.5.7 and below, as well as all versions of 4.4. This issue allows a remote, non-authenticated attacker to delete files on the system by sending a crafted POST request. Notably, deleting certain configuration files resets the Admin password to its default value. This vulnerability poses a significant risk to FortiWAN users and requires immediate mitigation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FortiWAN
Affected Vendors
- Fortinet