Arbitrary file deletion in administrative interface

Summary

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in FortiVoice may allow a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.

Version Affected Solution
FortiVoice 7.4 Not affected Not Applicable
FortiVoice 7.2 7.2.0 through 7.2.2 Upgrade to 7.2.3 or above
FortiVoice 7.0 7.0.0 through 7.0.7 Upgrade to 7.0.8 or above

Acknowledgement

Internally reported and discovered by Jaguar Perlas of Burnaby Infosec team.

Timeline

2026-01-13: Initial publication