CVE-2021-22126: Medium severity Fortinet FortiWLC vulnerability
A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenticated attacker to connect to the managed Access Point (Meru AP and FortiAP-U) as root using the default hard-coded username and password.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22126?
CVE-2021-22126 has a high severity rating due to the presence of a hard-coded password that allows local authenticated access.
How do I fix CVE-2021-22126?
To fix CVE-2021-22126, update to FortiWLC version 8.5.3 or later, or apply the vendor-recommended patches.
Who is affected by CVE-2021-22126?
CVE-2021-22126 affects users of FortiWLC versions 8.5.2 and below, as well as versions 8.4.8 and below, and specific earlier versions.
What types of devices are vulnerable to CVE-2021-22126?
CVE-2021-22126 affects managed Access Points, including Meru AP and FortiAP-U devices.
Can CVE-2021-22126 be exploited remotely?
No, CVE-2021-22126 requires local authenticated access for exploitation.