First published: Wed Jul 07 2021(Updated: )
An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 may allow an authenticated attacker to execute unauthorized commands by running the kdbg CLI command with specifically crafted arguments.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAP | >=6.4.1<6.4.6 | |
Fortinet Fortiap-s | >=6.2.4<6.2.6 | |
Fortinet FortiAP-W2 | >=6.2.4<6.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26106 is an OS Command vulnerability in FortiAP's console version 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5.
An authenticated attacker can execute unauthorized commands by running the kdbg CLI command with specifically crafted arguments.
FortiAP's console versions 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 are affected.
CVE-2021-26106 has a severity rating of 7.8 (high).
Update FortiAP's console to version 6.4.6 or higher for 6.4.x series, and 6.2.6 or higher for 6.2.x series.