Multiple OS command injection in Web Vulnerability Scanner

Summary

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC may allow an authenticated attacker to execute unauthorized code via crafted HTTP requests.

Version Affected Solution
FortiADC 8.0 Not affected Not Applicable
FortiADC 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.2 or above
FortiADC 7.4 7.4.0 through 7.4.6 Upgrade to 7.4.7 or above
FortiADC 7.2 7.2.0 through 7.2.7 Upgrade to 7.2.8 or above
FortiADC 7.1 7.1.0 through 7.1.4 Upgrade to 7.1.5 or above
FortiADC 7.0 7.0 all versions Migrate to a fixed release
FortiADC 6.2 6.2 all versions Migrate to a fixed release
FortiADC 6.1 6.1 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Kentaro Kawane from GMO Cybersecurity by Ierae for reporting this vulnerability under responsible disclosure.

Timeline

2025-06-10: Initial publication