以下是该漏洞描述的中文翻译: 在 Fortinet FortiSandbox 5.2.0、FortiSandbox 5.0.0 至 5.0.6 以及 FortiSandbox 4.4.0 至 4.4.9 版本中存在一个由特殊字符处理不当引发的命令注入(Command Injection)漏洞。攻击者可能借此执行未经授权代码或命令,具体攻击向量为 <在此处插入攻击向量>。 翻译说明: Improper neutralization of special elements:译为“特殊字符处理不当”。 Command i
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Fortinet | FortiSandbox | 5.2.0 |
affected |
5.0.0≤ 5.0.6 |
affected | ||
4.4.0≤ 4.4.9 |
affected | ||
4.2.1≤ 4.2.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fortinet | FortiSandbox | 5.2.0 |
cpe:2.3:a:fortinet:fortisandbox:5.2.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-26084 | 8.9 HIGH | FortiSandbox 4.4.8/5.0.5 访问控制缺陷 |
| CVE-2026-84393 | 7.3 HIGH | FortiOS 7.6.1-7.6.6证书主机不匹配漏洞 |
| CVE-2026-84391 | 5.9 MEDIUM | FortiAnalyzer 7.6.3-7.6.6 未初始化变量致拒绝服务 |
| CVE-2026-84385 | 4.9 MEDIUM | FortiSOAR 7.3-7.6 权限提升漏洞 |
| CVE-2026-22575 | 4.7 MEDIUM | FortiManager 7.x 访问控制缺陷 |
| CVE-2026-84386 | 4.7 MEDIUM | FortiClient Windows 7.4.0-7.4.7 未验证所有权 |
| CVE-2026-84389 | 2.8 LOW | FortiSIEM 7.4/7.5 开放重定向漏洞 |
| CVE-2026-84392 | 2.5 LOW | FortiOS/FortiPAM空指针解引用漏洞 |
No comments yet