FortiAP - Restricted Shell Escape via CLI Command Injection

Summary

An improper neutralization of special elements used in an OS command [CWE-78] in FortiAP may allow a local authenticated attacker to execute unauthorized code via the FortiAP CLI.

Version Affected Solution
FortiAP 7.6 Not affected Not Applicable
FortiAP 7.4 7.4.0 through 7.4.2 Upgrade to 7.4.3 or above
FortiAP 7.2 7.2.0 through 7.2.3 Upgrade to 7.2.4 or above
FortiAP 7.0 7.0 all versions Migrate to a fixed release
FortiAP 6.4 6.4 all versions Migrate to a fixed release
FortiAP-S 6.4 6.4.0 through 6.4.9 Upgrade to 6.4.10 or above
FortiAP-S 6.2 6.2 all versions Migrate to a fixed release
FortiAP-W2 7.4 7.4.0 through 7.4.2 Upgrade to 7.4.3 or above
FortiAP-W2 7.2 7.2.0 through 7.2.3 Upgrade to 7.2.4 or above
FortiAP-W2 7.0 7.0 all versions Migrate to a fixed release
FortiAP-W2 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Christian Hilgers from indevis for reporting this vulnerability under responsible disclosure

Timeline

2025-01-14: Initial publication