Fortinet FortiWLM是美国飞塔(Fortinet)公司的一个无线管理器。 Fortinet FortiWLM 8.6.0版本至8.6.5版本和8.5.0版本至8.5.4版本存在代码注入漏洞,该漏洞源于相对路径遍历问题,允许攻击者通过精心构造的web请求执行未经授权的代码或命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-34990.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-48889 | 7.2 HIGH | Fortinet FortiManager 操作系统命令注入漏洞 |
| CVE-2024-50570 | 4.9 MEDIUM | Fortinet FortiClient 安全漏洞 |
No comments yet