The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.
2017-02-01T17:59:00.153
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:N
10.0
9.2
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Hardware | fortinet | fortiwlc | 7.0-9-1 | Yes |
Hardware | fortinet | fortiwlc | 7.0-10-0 | Yes |
Hardware | fortinet | fortiwlc | 8.1-2-0 | Yes |
Hardware | fortinet | fortiwlc | 8.1-3-2 | Yes |
Hardware | fortinet | fortiwlc | 8.2-4-0 | Yes |