CVE-2021-26115
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Dec 19, 2024
CWE ID 78
Summary
CVE-2021-26115 is an OS command injection vulnerability affecting FortiWAN versions 4.5.7 and below in their Command Line Interface. An attacker who is locally authenticated and unprivileged can exploit this CWE-78 vulnerability to escalate their privileges to root by executing a carefully crafted command. This weakness allows unauthorized escalation of access, potentially compromising the entire FortiWAN system. This vulnerability underscores the importance of keeping software up-to-date to protect against known security risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FortiWAN
Affected Vendors
- Fortinet