OS command injection on diagnose feature (GUI)

Summary

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiIsolator may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code via specifically crafted HTTP requests.

Version Affected Solution
FortiIsolator 3.0 Not affected Not Applicable
FortiIsolator 2.4 2.4.3 through 2.4.6 Upgrade to 2.4.7 or above
FortiIsolator 2.3 Not affected Not Applicable
FortiIsolator 2.2 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Timeline

2025-04-08: Initial publication