An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management AP script download webUI page allows an authenticated admin user to execute arbitrary system console commands via crafted HTTP requests.
2017-10-26T13:29:00.370
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiwlc | ≤ 6.1-5 | Yes |
Application | fortinet | fortiwlc | ≤ 7.0-10 | Yes |
Application | fortinet | fortiwlc | ≤ 8.2 | Yes |
Application | fortinet | fortiwlc | ≤ 8.3.2 | Yes |