FG-IR-21-163: Command injection in CLI
An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiAP, FortiAP-S, FortiAP-W2 and FortiAP-U may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-21-163?
The severity of FG-IR-21-163 is considered critical due to the potential for unauthorized command execution.
How do I fix FG-IR-21-163?
To fix FG-IR-21-163, update the affected FortiAP devices to the latest firmware version provided by Fortinet.
Who is affected by FG-IR-21-163?
FG-IR-21-163 affects users of Fortinet FortiAP, FortiAP-S, FortiAP-W2, and FortiAP-U.
What type of vulnerability is FG-IR-21-163?
FG-IR-21-163 is classified as an OS command injection vulnerability.
Can FG-IR-21-163 be exploited remotely?
Yes, FG-IR-21-163 can potentially be exploited by an authenticated attacker who has access to the command line interpreter.