Unauthenticated command injection vulnerability

Summary

Multiple improper neutralization of special elements used in an os command ("OS command injection") vulnerabilities [CWE-78] in FortiWLM may allow a remote unauthenticated attacker to execute unauthorized commands via specifically crafted http get request parameters.

Version Affected Solution
FortiWLM 8.6 8.6.0 through 8.6.5 Upgrade to 8.6.6 or above
FortiWLM 8.5 8.5.0 through 8.5.4 Upgrade to 8.5.5 or above

Acknowledgement

Fortinet is pleased to thank security researchers Zach Hanley (@hacks_zach) of Horizon3.ai for discovering and reporting this vulnerability under responsible disclosure.

Timeline

2023-09-29: Initial publication