Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands via CLI commands including special characters
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
Fortinet FortiExtender 操作系统命令注入漏洞
Vulnerability Description
Fortinet FortiExtender是美国飞塔(Fortinet)公司的一款无线WAN(广域网)扩展器设备。 Fortinet FortiExtender 7.0.1及之前版本、4.2.3及之前版本、4.1.7及之前版本存在操作系统命令注入漏洞,该漏洞允许经过身份验证的攻击者通过CLI命令(包括特殊字符)执行特权shell命令。
CVSS Information
N/A
Vulnerability Type
N/A