FortiWeb - Stack overflow in execute backup command

Summary

A stack-based buffer overflow vulnearbility [CWE-121] in Fortiweb's backup command may allow a privileged user to execute arbitrary code via specially crafted CLI commands, provided the user is able to evade FortiWeb stack protections.

Version Affected Solution
FortiWeb 7.6 Not affected Not Applicable
FortiWeb 7.4 7.4.0 through 7.4.1 Upgrade to 7.4.2 or above
FortiWeb 7.2 7.2.0 through 7.2.7 Upgrade to 7.2.8 or above
FortiWeb 7.0 Not affected Not Applicable
FortiWeb 6.4 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Cody Sixteen for reporting this vulnerability under responsible disclosure.

Timeline

2025-01-14: Initial publication