CVE-2021-26106: [FortiAP] OS command Injection through hidden kdbg CLI command
An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 may allow an authenticated attacker to execute unauthorized commands by running the kdbg CLI command with specifically crafted arguments.
Other sources
An instance of improper neutralization of special elements used in an OS Command found in FortiAP's console may allow an authenticated attacker to execute unauthorized commands by running the kdbg CLI command with specifically crafted arguments.
— FortiGuard
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26106?
CVE-2021-26106 is an OS Command vulnerability in FortiAP's console version 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5.
How can an attacker exploit CVE-2021-26106?
An authenticated attacker can execute unauthorized commands by running the kdbg CLI command with specifically crafted arguments.
Which software versions are affected by CVE-2021-26106?
FortiAP's console versions 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 are affected.
What is the severity of CVE-2021-26106?
CVE-2021-26106 has a severity rating of 7.8 (high).
How can I fix CVE-2021-26106?
Update FortiAP's console to version 6.4.6 or higher for 6.4.x series, and 6.2.6 or higher for 6.2.x series.