CVE-2023-25608: FortiAP's - Arbitrary file read through the CLI
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-W2 7.2.0 through 7.2.1, 7.0.3 through 7.0.5, 7.0.0 through 7.0.1, 6.4 all versions, 6.2 all versions, 6.0 all versions; FortiAP-C 5.4.0 through 5.4.4, 5.2 all versions; FortiAP 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions, 6.0 all versions; FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to read arbitrary files via specially crafted command arguments.
Other sources
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP, FortiAP-W2, FortiAP-U, FortiAP-C may allow an authenticated attacker to read arbitrary files via specially crafted command arguments.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-25608.
What is the severity of CVE-2023-25608?
The severity of CVE-2023-25608 is medium with a severity value of 6.5.
Which versions of FortiAP-W2 are affected by CVE-2023-25608?
FortiAP-W2 versions 7.2.0 through 7.2.1, 7.0.3 through 7.0.5, 7.0.0 through 7.0.1, 6.4 all versions, 6.2 all versions, and 6.0 all versions are affected.
Which versions of FortiAP-C are affected by CVE-2023-25608?
FortiAP-C versions 5.4.0 through 5.4.4 and 5.2 all versions are affected.
How can I fix CVE-2023-25608?
To fix CVE-2023-25608, update FortiAP-W2 to versions 7.2.2 or later, update FortiAP-C to version 5.4.5 or later, or apply the necessary patches or upgrades as recommended by Fortinet.