OS Command Injections

Summary

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') [CWE-78] in FortiWeb API endpoints may allow an authenticated attacker with admin privileges to execute arbitrary code or commands on the underlying system via crafted requests.

Version Affected Solution
FortiWeb 7.6 7.6.0 Upgrade to 7.6.1 or above
FortiWeb 7.4 7.4.0 through 7.4.5 Upgrade to 7.4.6 or above
FortiWeb 7.2 7.2 all versions Migrate to a fixed release
FortiWeb 7.0 7.0 all versions Migrate to a fixed release
FortiWeb 6.4 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Kentaro Kawane of GMO Cybersecurity by Ierae working with Trend Micro Zero Day Initiative for reporting these two vulnerabilities under responsible disclosure.

Timeline

2025-02-11: Initial publication