shell command limitation bypass by SSH local config overriding

Summary

An Improper Access Control vulnerability [CWE-284] in FortiSwitchAXFixed may allow an authenticated admin to execute system commands via a specifically crafted SSH config file.

Version Affected Solution
FortiSwitchAXFixed 1.0 1.0.0 through 1.0.1 Upgrade to 1.0.2 or above

Acknowledgement

Internally discovered and reported by Yonghui Han of Fortinet Product Security team.

Timeline

2026-03-10: Initial publication