shell command limitation bypass by SSH local config overriding
Summary
An Improper Access Control vulnerability [CWE-284] in FortiSwitchAXFixed may allow an authenticated admin to execute system commands via a specifically crafted SSH config file.
| Version | Affected | Solution |
|---|---|---|
| FortiSwitchAXFixed 1.0 | 1.0.0 through 1.0.1 | Upgrade to 1.0.2 or above |
Acknowledgement
Internally discovered and reported by Yonghui Han of Fortinet Product Security team.Timeline
2026-03-10: Initial publication