CVE-2023-36634
HIGHFortiAP-U <7.0.0, <6.2.5, <=6.0, <=5.4 - Command Injection
Title source: llmDescription
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbitrary files and directory via specially crafted command arguments.
References (1)
Scores
CVSS v3
7.1
EPSS
0.0013
EPSS Percentile
31.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Classification
CWE
CWE-73
Status
published
Affected Products (2)
fortinet/fortiap-u
< 5.4.6
fortinet/fortiap-u
Timeline
Published
Sep 13, 2023
Tracked Since
Feb 18, 2026